Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors puNK-003

Also known as: Jennifer Anderson, lead, BlackCat, Gookee, kapuchin0, Guki, Winnti Umbrella, Royal Ransomware, leaked the source code, shut the operation down, employees at target organizations

Description

puNK-003 is a North Korean cyber espionage group that has been linked to the use of a high‑complexity C++ Remote Access Trojan (RAT) known as Lilith. The RAT is delivered via spear‑phishing campaigns that embed malicious LNK shortcuts—an approach that bypasses many conventional email defenses. Once installed, Lilith provides full remote control of compromised hosts and can persist using legitimate registry locations or scheduled tasks. The group also deploys an AutoIt downloader named CURKON to fetch additional modules from infrastructure the actors control. The actor’s technical footprint demonstrates clear parallels with the Konni group, notably in the use of AutoIt scripting and specific coding idioms such as obfuscated string handling and encoded payloads. In addition to the RAT, puNK-003 is believed to ship ransomware variants linked to BlackCat and Akira—both known for double‑extortion tactics that combine data exfiltration with encryption. Operationally, the group targets high‑value sectors worldwide (including CN, RU, IR, IN, UA, GB, DE, KP, IL, SA, US, PK, BY, PL, TW, CA, AU). Their goal appears to be a blend of financial theft and strategic intelligence gathering: exfiltrating valuable data for future exploitation while also forcing victims into ransom payments. Indicators of compromise include unusual network traffic, frequent LNK file downloads, and execution of the kernel driver iqvw64.sys—an exploit targeting Intel Ethernet components. Removal typically requires a combination of specialized anti‑virus signatures against Lilith/CURKON binaries and manual endpoint clean‑up procedures that reset affected registry keys and scheduled tasks. The group remains active, regularly updating its delivery methods to evade detection by modern EDR solutions. Overall, puNK-003 exemplifies the evolving threat landscape posed by state‑sponsored actors that blend espionage tactics with ransomware economics—making them formidable adversaries for any organization in their target sectors.

Goals & Targeting

Targeted Sectors

Financial services
Government
Telecommunications
Defense
Education
Healthcare
Critical infrastructure
Retail
Hospitality
Non profit
Media
Information technology
Manufacturing
Gaming
Utilities
Aerospace
Maritime
Nuclear
Entertainment
Food agriculture
Construction
Transportation
Critical infrastructure

Targeted Countries / Regions

CN
RU
IR
IN
UA
GB
DE
KP
IL
SA
US
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· 3 days ago

Executive Summary

puNK-003 is a North Korean APT group that employs the Lilith Remote Access Trojan and an AutoIt downloader called CURKON to compromise systems via malicious LNK files. The actors target a broad array of sectors—including finance, government, critical infrastructure, healthcare, and telecommunications—across multiple countries with primarily financial gain objectives and a double‑extortion ransomware component. Their operations rely on sophisticated social engineering, credential theft, and lateral movement techniques to exfiltrate data before encrypting it.

Goals & Targeting

The strategic objectives of puNK-003 appear to center on two primary goals: (1) financial gain through double‑extortion ransomware, and (2) acquiring actionable intelligence from high‑value entities across government, critical infrastructure, finance, and technology. By targeting countries such as China, Russia, Iran, India, Ukraine, the UK, Germany, North Korea, Israel, Saudi Arabia, the US, Pakistan, Belarus, Poland, Taiwan, Canada, and Australia, they seek to leverage geographic diversity to maximize data access and reduce attribution risk. Victims are usually mid‑size to large organizations with complex IT environments; the group employs phishing, credential theft, and exploitation of public‑facing applications to breach perimeter defenses before deploying its RATs and ransomware payloads. The actor’s focus on domains like telecommunication providers, manufacturing, and energy utilities indicates an intent not only to profit but also potentially to undermine critical national infrastructure—a hallmark of North Korean cyber operations. Typical victims include institutions with significant customer data or operational technology assets—in short, organizations that can provide both lucrative ransom leverage and sensitive information for long‑term state objectives.

Enhanced Description

Key Capabilities

  • Deploys Lilith RAT via malicious LNK files
  • Uses AutoIt downloader CURKON to fetch additional payloads
  • Employs spear‑phishing and social engineering against IT staff
  • Exploits public‑facing application vulnerabilities (e.g., CVE-2015-2291, CVE-2021-35464)
  • Conducts credential dumping with Mimikatz/LaZagne
  • Performs domain trust discovery and Azure/AWS reconnaissance
  • Uses legitimate utilities (AnyDesk, PuTTy, Rclone) for lateral movement
  • Implements double‑extortion strategy by exfiltrating data before encryption
  • Encrypts victim files with BlackCat or Akira ransomware variants
  • Leverages command‑and‑control over DNS, HTTP, and encrypted tunnels

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control
Impact
Resource Development

ATT&CK Techniques

T1583.001
T1006
T1543.003
T1133
T1114.001
T1564.001
T1530
T1190
T1558.001
T1555.002
T1567.001
T1219
T1036
T1589.001
T1560
T1021.004
T1580.001
T1217
T1087
T1059.003
T1482
T1070.001
T1083
T1074
T1657
T1041
T1098
T1048
T1078
T1068
T1531
T1027
T1486
T1685
T1585
T1213
T1136
T1018
T1538
T1484

Software / Tooling

Lilith RAT
CURKON (AutoIt downloader)
BlackCat ransomware
Akira ransomware
Mimikatz
LaZagne
PowerShell
Cobalt Strike
AnyDesk
PuTTy
Rclone
Ntlm.dll
iqvw64.sys kernel driver
ngrok
Teleport

Campaigns & Victims

Since its emergence, puNK-003 has adopted a hybrid campaign model that incorporates both espionage and ransomware components. The group typically begins with phishing or credential‑stealing operations, then leverages internal network lateral movement via tools like AnyDesk and PuTTy before deploying the Lilith RAT for persistence. Once a foothold is established, they conduct comprehensive discovery—including domain trust checks and cloud resource enumeration—to identify high‑value data sets. Exfiltration is performed over HTTP/DNS or alternative protocols before encrypting critical files with BlackCat or Akira ransomware to enforce a double‑extortion payoff. The actor’s operational tempo varies; during peak periods, they have launched simultaneous attacks across multiple countries, often targeting sectors that provide both immediate ransom revenue and strategic intelligence. Their use of fast‑flux domains for C2, coupled with social engineering tactics such as pretending to be IT help‑desk personnel, showcases a high level of sophistication and adaptability. Notable past operations include the deployment of BlackCat ransomware against telecommunication providers in the UK, the exploitation of CVE‑2015‑2291 through iqvw64.sys attacks reported by security researchers, and an Akira‑related ransomware sweep that targeted manufacturing firms in several European countries.

IOC Patterns

  • Spear‑phishing emails with malicious LNK shortcuts
  • Suspicious domains such as attack.mitre.org, cisa.gov, Temp.Zagros, TEMP.Akapav
  • C2 communications over fast‑flux DNS domains (e.g., Teleport.sh)
  • Evidence of kernel driver installs involving iqvw64.sys
  • Use of file hosting services (trycloudflare.com, paste.ee, file.io) for delivery

Recommended Actions

  • Enforce multi‑factor authentication across all remote access points and immediately revoke compromised credentials
  • Block known malicious LNK attachments by configuring email gateways to detect and quarantine them
  • Deploy endpoint protection that identifies AutoIt scripts and Lilith RAT binaries, using both signatures and behavioral analytics
  • Patch identified vulnerabilities such as CVE‑2015‑2291 and CVE‑2021‑35464 before they can be exploited
  • Segment network zones to limit lateral movement and isolate critical subsystems from general user access
  • Implement continuous monitoring for anomalous AD trust changes and remote service usage
  • Conduct regular phishing awareness training and simulation exercises focusing on LNK file indicators
  • Establish rapid incident response playbooks specifically for double‑extortion scenarios, including data backup verification
  • Integrate threat intelligence feeds with indicators such as the domains, IP ranges, and file hashes linked to puNK‑003 into security controls
  • Apply strict egress filtering for DNS and HTTP traffic to detect and block suspicious exfiltration channels

Suggested Tags

APT
North Korean
Ransomware-as-a-Service
Critical infrastructure
Finance sector
Government espionage
Credential theft
Social engineering
Double‑extortion

Confidence Assessment

The profiling of puNK-003 is drawn mainly from publicly available analytical reports, which combine observed technical artifacts (e.g., Lilith RAT, CURKON downloader) with attribution patterns typical of North Korean actors. While the core capabilities and tactics are well corroborated through multiple security vendor publications, details about internal structure, precise motives beyond financial gain, and recent activity are sparse or dated. Consequently, confidence in known tool usage and campaign tactics is medium to high; however, specifics regarding the actor’s current operational tempo, future plans, or any novel techniques remain uncertain.

ATT&CK Techniques

Command & Control
1 technique
Lateral Movement
2 techniques
Privilege Escalation
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  2. attack.mitre.org — Cited by web research for: employees at target organizations
  3. attack.mitre.org — Cited by web research for: T1486
  4. www.huntress.com — Cited by web research for: Unknown
  5. https://unit42.paloaltonetworks.com/punk-spider — Cited by AI analysis.
  6. https://unit42.paloaltonetworks.com/akra-variant — Cited by AI analysis.
  7. https://www.fireeye.com/current-threats/incident-reports.html — Cited by AI analysis.

Intel Summary

52

Techniques

47

Tools

1

Campaigns

14

IOCs

0

Observed Data

16

Tactics

Tags

APT
Phishing
Backdoor / C2
North Korean
Ransomware-as-a-Service
Critical infrastructure
Finance sector
Government espionage
Credential theft
Social engineering
Double‑extortion

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.