Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Wassonite

Also known as: Silent Chollima, Stonefly, Onyx Sleet, DarkSeoul, TEMP.Firework, Black Banshee, Bureau 121, Lab 110, WICKED PANDA

Description

Wassonite (also known by aliases Silent Chollima and Black Banshee) is linked to the North Korea‑based Lazarus Group and has repeatedly targeted high‑value industrial control environments across Asia since 2018. The gang's operations are primarily centered on information gathering, credential theft and data exfiltration rather than sabotage. Attackers first establish footholds through spear‑phishing or drive‑by compromises that deliver the DTrack RAT—an advanced remote access trojan capable of persisting via a custom WBService component and masquerading as legitimate utilities such as OllyDbg or 7‑Zip. Once inside, Wassonite employs Mimikatz to harvest domain credentials and uses the collected passwords for lateral movement across network shares. Its reconnaissance toolkit includes system discovery commands (ipconfig, netstat) and registry queries to gather host information, while exfiltration is performed by staging data into encrypted or password‑protected archives before transferring it through inbound channels like HTTP/S or SMB. The group also integrates a keylogging module that captures screen activity and keystrokes, further enriching the intelligence payload. Despite its stealthy posture, Wassonite avoids destructive actions; there are no documented incidents of plant sabotage or significant operational disruption. However, its continued use of sophisticated credential theft, persistence mechanisms, and data‑exfiltration techniques make it a persistent threat to critical infrastructure sectors such as nuclear energy, manufacturing, finance and maritime transport.

Goals & Targeting

Targeted Sectors

Nuclear
Manufacturing
Financial services
Energy
Defense
Government
Oil gas
Maritime
Food agriculture
Media
Critical infrastructure

Targeted Countries / Regions

IN
KR
JP
KP
RU
CN
IR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Wassonite is a North‑Korean espionage-focused APT that has been active since at least 2018, targeting industrial control sectors—including nuclear facilities—in India, South Korea and Japan. The group employs the DTrack RAT to gain remote footholds, steals credentials with Mimikatz, and exfiltrates data by staging it in password‑protected archives. While lacking known destructive capabilities, its toolset mirrors that of other Lazarus Group campaigns such as DarkSeoul.

Goals & Targeting

Wassonite's strategic objective is long‑term intelligence collection from assets that influence national security, economic stability and geopolitical leverage. The group prioritizes high‑value targets—including nuclear power facilities, manufacturing plants, financial services firms and critical infrastructure—primarily in India, South Korea, Japan, Iran, Russia and China. Their targeting approach blends social engineering with exploitative lateral movement to gain deep situational insight while maintaining a low profile to avoid detection. The APT appears motivated by state‑level espionage, seeking information that could inform political or economic advantage for its sponsoring nation rather than direct sabotage. Consequently, the focus remains on reconnaissance, data harvesting and covert exfiltration rather than active disruption.

Enhanced Description

Key Capabilities

  • remote access via DTrack RAT
  • credential theft with Mimikatz
  • lateral movement using hard‑coded credentials and system tools
  • data staging and exfiltration through password‑protected archives
  • IP enumeration via ipconfig command
  • system network connection discovery
  • persistent service (WBService) and autostart entries
  • keylogging component
  • masquerading as legitimate programs (OllyDbg/7‑Zip/FileZilla)
  • encrypted payload delivery

MITRE ATT&CK Tactics

Collection
Persistence
Discovery
Execution
Defense Evasion
Exfiltration

ATT&CK Techniques

T1560
T1547
T1217
T1059.003
T1543.003
T1005
T1074.001
T1140
T1083
T1574
T1070.004
T1105
T1056.001
T1036.005
T1027.009
T1012
T1129
T1082
T1016
T1049
T1078
T1055
T1543
T1592
T1590

Software / Tooling

DTrack
Mimikatz
AppleSeed

Campaigns & Victims

Since 2018, Wassonite has repeatedly infiltrated nuclear power facilities such as India’s Kudankulam plant and other industrial control environments in South Korea and Japan. The operational tempo has been sporadic but sustained, typically launching reconnaissance or credential‑stealing phases before staging exfiltration. Victims range from energy sector utilities to financial institutions and manufacturing plants; the group favors organizations with complex network architectures and multiple administrative domains to extend coverage. Key patterns include spear‑phishing lures themed around nuclear or industrial content, the use of a custom RAT that installs a hidden service for persistence, and exfiltration via encrypted archives transmitted over standard protocols (HTTPS, SMB). The group has not been observed deploying destructive payloads—their activities align more closely with intelligence gathering than sabotage. Notable operations identified include a 2020 incident at the Kudankulam Nuclear Power Plant in India involving DTrack deployment and credential harvesting; earlier analysis links similar toolsets to Lazarus Group campaigns such as DarkSeoul, indicating common operational staff or shared R&D capabilities.

IOC Patterns

  • password-protected archives
  • autostart persistence files
  • service named WBService
  • keystroke logging component
  • masquerading as legitimate programs (OllyDbg/7‑Zip/FileZilla)
  • encrypted payload delivery
  • IP enumeration via ipconfig
  • system network connection discovery
  • hard-coded credentials for shared resources

Recommended Actions

  • Deploy EDR solutions to detect DTrack indicators such as the WBService process and keylogger binaries.
  • Enforce multi‑factor authentication and strict least‑privilege policies to mitigate credential theft by Mimikatz.
  • Monitor for abnormal autostart registry entries, unexpected service creations, or privileged account logons.
  • Detect and block unauthorized process injection/hijacking techniques (e.g., T1055).
  • Audit registry values and system configuration for anomalies regularly.
  • Implement network segmentation and access controls on shared resources to limit lateral movement.
  • Alert on anomalous use of ipconfig or netstat commands indicating IP discovery in idle hosts.
  • Establish baseline for CMDB data transfers and monitor exfiltration patterns from critical infrastructure management systems.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: T1547
  2. apt.etda.or.th — Cited by web research for: Mimikatz
  3. www.dragos.com — Cited by web research for: CALENDAR
  4. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  5. hub.dragos.com — Cited by web research for: Critical Infrastructure

Intel Summary

33

Techniques

34

Tools

0

Campaigns

6

IOCs

0

Observed Data

7

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.