SYMBOLCOMMON_NAMEaka. SYNONYMS

BlueHornet  (Back to overview)

aka: APT49, AgainstTheWest

BlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked data from other APT groups like Kryptonite Panda and Lazarus Group. BlueHornet has been involved in campaigns such as Operation Renminbi, Operation Ruble, and Operation EUSec, focusing on exfiltrating region-specific data and selling it on the dark web. They have also been known to collaborate with different threat actors and have recently disclosed a zero-day exploit in NGINX 1.18.


Associated Families

There are currently no families associated with this actor.


References
2023-07-20MandiantMandiant Intelligence
KillNet Showcases New Capabilities While Repeating Older Tactics
BlueHornet Zarya
2023-01-04CSO OnlineApurva Venkat
Cyberattacks against governments jumped 95% in last half of 2022, CloudSek says
BlueHornet
2022-04-14CyberIntCyberint Research
BlueHornet – One APT to Terrorize Them All
BlueHornet

Credits: MISP Project