Also known as: Jennifer Anderson, lead, BlackCat, Gookee, kapuchin0, Guki, Winnti Umbrella, Royal Ransomware, leaked the source code, shut the operation down, employees at target organizations
puNK-003 is a North Korean cyber espionage group that has been linked to the use of a high‑complexity C++ Remote Access Trojan (RAT) known as Lilith. The RAT is delivered via spear‑phishing campaigns that embed malicious LNK shortcuts—an approach that bypasses many conventional email defenses. Once installed, Lilith provides full remote control of compromised hosts and can persist using legitimate registry locations or scheduled tasks. The group also deploys an AutoIt downloader named CURKON to fetch additional modules from infrastructure the actors control. The actor’s technical footprint demonstrates clear parallels with the Konni group, notably in the use of AutoIt scripting and specific coding idioms such as obfuscated string handling and encoded payloads. In addition to the RAT, puNK-003 is believed to ship ransomware variants linked to BlackCat and Akira—both known for double‑extortion tactics that combine data exfiltration with encryption. Operationally, the group targets high‑value sectors worldwide (including CN, RU, IR, IN, UA, GB, DE, KP, IL, SA, US, PK, BY, PL, TW, CA, AU). Their goal appears to be a blend of financial theft and strategic intelligence gathering: exfiltrating valuable data for future exploitation while also forcing victims into ransom payments. Indicators of compromise include unusual network traffic, frequent LNK file downloads, and execution of the kernel driver iqvw64.sys—an exploit targeting Intel Ethernet components. Removal typically requires a combination of specialized anti‑virus signatures against Lilith/CURKON binaries and manual endpoint clean‑up procedures that reset affected registry keys and scheduled tasks. The group remains active, regularly updating its delivery methods to evade detection by modern EDR solutions. Overall, puNK-003 exemplifies the evolving threat landscape posed by state‑sponsored actors that blend espionage tactics with ransomware economics—making them formidable adversaries for any organization in their target sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
puNK-003 is a North Korean APT group that employs the Lilith Remote Access Trojan and an AutoIt downloader called CURKON to compromise systems via malicious LNK files. The actors target a broad array of sectors—including finance, government, critical infrastructure, healthcare, and telecommunications—across multiple countries with primarily financial gain objectives and a double‑extortion ransomware component. Their operations rely on sophisticated social engineering, credential theft, and lateral movement techniques to exfiltrate data before encrypting it.
Goals & Targeting
The strategic objectives of puNK-003 appear to center on two primary goals: (1) financial gain through double‑extortion ransomware, and (2) acquiring actionable intelligence from high‑value entities across government, critical infrastructure, finance, and technology. By targeting countries such as China, Russia, Iran, India, Ukraine, the UK, Germany, North Korea, Israel, Saudi Arabia, the US, Pakistan, Belarus, Poland, Taiwan, Canada, and Australia, they seek to leverage geographic diversity to maximize data access and reduce attribution risk. Victims are usually mid‑size to large organizations with complex IT environments; the group employs phishing, credential theft, and exploitation of public‑facing applications to breach perimeter defenses before deploying its RATs and ransomware payloads. The actor’s focus on domains like telecommunication providers, manufacturing, and energy utilities indicates an intent not only to profit but also potentially to undermine critical national infrastructure—a hallmark of North Korean cyber operations. Typical victims include institutions with significant customer data or operational technology assets—in short, organizations that can provide both lucrative ransom leverage and sensitive information for long‑term state objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its emergence, puNK-003 has adopted a hybrid campaign model that incorporates both espionage and ransomware components. The group typically begins with phishing or credential‑stealing operations, then leverages internal network lateral movement via tools like AnyDesk and PuTTy before deploying the Lilith RAT for persistence. Once a foothold is established, they conduct comprehensive discovery—including domain trust checks and cloud resource enumeration—to identify high‑value data sets. Exfiltration is performed over HTTP/DNS or alternative protocols before encrypting critical files with BlackCat or Akira ransomware to enforce a double‑extortion payoff. The actor’s operational tempo varies; during peak periods, they have launched simultaneous attacks across multiple countries, often targeting sectors that provide both immediate ransom revenue and strategic intelligence. Their use of fast‑flux domains for C2, coupled with social engineering tactics such as pretending to be IT help‑desk personnel, showcases a high level of sophistication and adaptability. Notable past operations include the deployment of BlackCat ransomware against telecommunication providers in the UK, the exploitation of CVE‑2015‑2291 through iqvw64.sys attacks reported by security researchers, and an Akira‑related ransomware sweep that targeted manufacturing firms in several European countries.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The profiling of puNK-003 is drawn mainly from publicly available analytical reports, which combine observed technical artifacts (e.g., Lilith RAT, CURKON downloader) with attribution patterns typical of North Korean actors. While the core capabilities and tactics are well corroborated through multiple security vendor publications, details about internal structure, precise motives beyond financial gain, and recent activity are sparse or dated. Consequently, confidence in known tool usage and campaign tactics is medium to high; however, specifics regarding the actor’s current operational tempo, future plans, or any novel techniques remain uncertain.
Bayer Cyber Attack
No observed data linked yet.
52
Techniques
47
Tools
1
Campaigns
14
IOCs
0
Observed Data
16
Tactics