• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2026-88771

    Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

    Kiteworks shutdown advisory

    Kiteworks Systems Went Offline After Federal Threat Warning

    Dyfed-Powys Police cyberattack

    Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation

    weekly roundup The Cyber Express TCE Sep 2026

    The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act

    AI security risks

    Sam Altman at UN Security Council: 6 AI Security Risks the World Cannot Ignore

    Duelbits crypto hack

    Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains

    Burnaby School District cyberattack

    Burnaby Schools Hit by Cyberattack, Disrupting Networks and Phone Lines

    ban on Discord

    Ban on Discord Lifted After Platform Commits to Work With DICT and CICC

    Apache Tomcat Update

    Apache Tomcat Update: 12 Security Flaws Fixed in Tomcat 11.0.26

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI security risks

    Sam Altman at UN Security Council: 6 AI Security Risks the World Cannot Ignore

    AI-enabled cyber attacks

    AI Gives Hackers an Edge Defenders Still Can’t Match, NCSC Warns

    Fraudulent SIM cards

    India’s DoT Warns Citizens Over SIM Fraud and IMEI Tampering

    EU cybersecurity incidents

    EU Cybersecurity Response Hampered by Critical Information Gaps

    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    GUARD Act

    US House Passes Bill to Help Police Track Down Scammers Targeting Seniors

    Emergency Security Protocol

    EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats

    Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking,

    EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act

    outage communications

    CISA, FBI Urge Clearer Communication During Major Outages

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Ukraine cybersecurity

    Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center

    UK cyberattack rate

    UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds

    Cyber Yodha Campaign

    Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

    UK Ukraine AI partnership

    Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

    Hims & Hers lawsuit

    FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2026-88771

    Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

    Kiteworks shutdown advisory

    Kiteworks Systems Went Offline After Federal Threat Warning

    Dyfed-Powys Police cyberattack

    Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation

    weekly roundup The Cyber Express TCE Sep 2026

    The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act

    AI security risks

    Sam Altman at UN Security Council: 6 AI Security Risks the World Cannot Ignore

    Duelbits crypto hack

    Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains

    Burnaby School District cyberattack

    Burnaby Schools Hit by Cyberattack, Disrupting Networks and Phone Lines

    ban on Discord

    Ban on Discord Lifted After Platform Commits to Work With DICT and CICC

    Apache Tomcat Update

    Apache Tomcat Update: 12 Security Flaws Fixed in Tomcat 11.0.26

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI security risks

    Sam Altman at UN Security Council: 6 AI Security Risks the World Cannot Ignore

    AI-enabled cyber attacks

    AI Gives Hackers an Edge Defenders Still Can’t Match, NCSC Warns

    Fraudulent SIM cards

    India’s DoT Warns Citizens Over SIM Fraud and IMEI Tampering

    EU cybersecurity incidents

    EU Cybersecurity Response Hampered by Critical Information Gaps

    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    GUARD Act

    US House Passes Bill to Help Police Track Down Scammers Targeting Seniors

    Emergency Security Protocol

    EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats

    Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking,

    EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act

    outage communications

    CISA, FBI Urge Clearer Communication During Major Outages

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Ukraine cybersecurity

    Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center

    UK cyberattack rate

    UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds

    Cyber Yodha Campaign

    Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

    UK Ukraine AI partnership

    Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

    Hims & Hers lawsuit

    FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

North Korea’s Cyber Evolution and China’s Storm-2077 Unveiled by Microsoft Analysts

Ashish Khaitan by Ashish Khaitan
November 25, 2024
in Firewall Daily, Cyber News, Gitex2022, Lockbit Ransomware News, Press Release
0
Chinese Threat Actor
928
SHARES
5.2k
VIEWS
Share on LinkedInShare on Twitter

Microsoft Threat Intelligence analysts has shared new insights into North Korean and Chinese threat actors. At the recent CYBERWARCON, cybersecurity analyst shared details into the rise of attacks, the evolution of threat actor tactics, and the strategies employed by various state-backed groups.  

Key highlights of the conference included detailed insights into North Korea’s cyber capabilities and the introduction of a new Chinese threat actor, Storm-2077, whose operations have been targeting government entities and organizations worldwide. 

North Korean Hackers: A Decade of Evolving Tactic

One of the most talked-about presentations at CYBERWARCON was titled “DPRK – All Grown Up,” where Microsoft analysts shared how North Korean threat actors have advanced their cyber capabilities over the past ten years.  

North Korea has successfully built an extensive computer network exploitation (CNE) capability, leveraging cutting-edge tools to steal billions of dollars, primarily in cryptocurrency, and target organizations involved with satellite systems and weapons technologies. 

The presentation highlighted the group’s expertise in exploiting zero-day vulnerabilities, using cryptocurrency technologies, and even blockchain and AI to enhance their attacks. As part of their ongoing efforts to circumvent global sanctions, North Korea has deployed IT workers in countries like Russia and China.  

These workers pose as individuals from non-North Korean nations, providing seemingly legitimate IT services while secretly generating revenue to fund North Korea’s weapons programs. 

Microsoft analysts emphasized the three primary objectives of North Korean threat actors: 

  1. Stealing money and cryptocurrency to fund the country’s weapons programs. 
  2. Gathering sensitive information regarding weapons systems and policy decisions. 
  3. Using IT work to generate revenue that directly supports North Korea’s military and cyber programs. 

Storm-2077: A New Chinese Threat Actor 

In addition to tracking North Korean cyber activities, Microsoft also provided an in-depth look into Storm-2077, a Chinese state-sponsored threat actor that has been active since at least January 2024.  

This group, which Microsoft has identified through extensive intelligence collection, has launched widespread attacks targeting a diverse range of sectors, including government agencies, non-governmental organizations (NGOs), and industries such as defense, aviation, telecommunications, and financial services. 

Storm-2077 is a highly sophisticated actor that conducts intelligence collection operations by exploiting phishing techniques and gaining access to compromised systems. They are notorious for using valid credentials and exploiting cloud-based applications to steal sensitive data, including emails, which may contain sign-in credentials, financial information, intellectual property, and confidential communications. 

Microsoft’s research into Storm-2077 has shown that the group is particularly adept at exfiltrating email data. By stealing credentials and gaining access to cloud applications like eDiscovery tools, Storm-2077 can access vast amounts of sensitive information without immediate detection. Their operations are designed to extract intelligence without leaving a trace, allowing them to use the data for future attacks or strategic purposes. 

Tracking and Attribution: Challenges in Cyber Operations 

A major challenge in tracking Chinese state-sponsored cyber operations, as discussed in the talk “No Targets Left Behind,” is the overlap in tactics used by various Chinese threat actors. As these groups continually adjust their methods to evade detection, it becomes increasingly difficult to distinguish between them. Microsoft’s analysts explained how they pieced together the activities of Storm-2077, drawing from overlapping attack patterns and identifying unique markers that allowed them to attribute these operations to the Chinese state. 

By meticulously tracking the group’s activities, Microsoft has identified a trend in the types of organizations targeted and the tools used. Storm-2077 primarily focuses on intelligence collection and aims to gather as much sensitive information as possible across multiple industries. This level of sophistication and persistence makes them a significant threat to national security and global industries alike. 

Sapphire Sleet: North Korean Attacks on Cryptocurrency 

In addition to its discussion of North Korean IT workers and state-sponsored cyber actors, Microsoft presented on the group known as Sapphire Sleet, a North Korean cyber unit that has been responsible for large-scale cryptocurrency theft. Operating since at least 2020, Sapphire Sleet has stolen millions of dollars in cryptocurrency from various companies. Their modus operandi includes social engineering techniques like posing as venture capitalists or recruiters to manipulate victims into downloading malware. 

In one particularly common tactic, Sapphire Sleet initiates online meetings under the guise of discussing potential investments. When the victim attempts to connect, they are met with a frozen screen or an error message, prompting them to reach out for technical support. This contact initiates the malware download, compromising the victim’s device and allowing the attacker to steal cryptocurrency and other sensitive data. 

Furthermore, the group has been observed using platforms like LinkedIn to pose as recruiters, reaching out to potential targets under the guise of job opportunities. They then trick victims into completing fraudulent skills assessments that lead to malware infections. 

The Role of North Korean IT Workers in Cyber Operations 

An increasingly concerning element of North Korean cyber activity involves the regime’s network of IT workers, who operate globally to generate revenue for the government. These workers, often located in countries like Russia and China, perform remote IT tasks for companies while secretly advancing North Korea’s cyber capabilities.  

Microsoft has tracked these workers’ activities, revealing a network of facilitators who assist them in creating fake profiles and job applications. This practice allows North Korea to bypass sanctions and generate significant income while continuing to fund its weapons programs. 

The North Korean IT worker network is considered a “triple threat” by Microsoft, as these workers: 

  1. Perform legitimate IT tasks to generate revenue. 
  2. Steal sensitive information, including intellectual property and trade secrets. 
  3. Potentially extort companies by threatening to release stolen data unless paid. 

The scale of this network is vast, with hundreds of fake profiles and portfolios used by these workers to gain employment through platforms like GitHub, LinkedIn, and Upwork. In some cases, AI tools such as Faceswap have been used to create convincing photos of North Korean IT workers, further complicating efforts to track and identify them. 

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: Chinese threat actorCYBERWARCONNorth Korean Threat ActorsSapphire SleetStorm-2077The Cyber ExpressThe Cyber Express News
Previous Post

DOJ Orders Google to Sell Chrome to End Search Monopoly: A Possible Game-Changer for Competition

Next Post

EY Identity Acquires J Group Consulting to Strengthen Privileged Access Management

Next Post
EYI acquisition

EY Identity Acquires J Group Consulting to Strengthen Privileged Access Management

Q1 2026 Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

CVE-2026-88771
Firewall Daily

Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

September 28, 2026
Kiteworks shutdown advisory
Cyber News

Kiteworks Systems Went Offline After Federal Threat Warning

September 28, 2026
Dyfed-Powys Police cyberattack
Cyber News

Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation

September 28, 2026
weekly roundup The Cyber Express TCE Sep 2026
Firewall Daily

The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act

September 25, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information