dprk-cyber-espionage

Maintain a living knowledge base of DPRK cyber espionage operations with source references.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill dprk-cyber-espionage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dprk-cyber-espionage
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/dprk-cyber-espionage
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill dprk-cyber-espionage

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides a living, authoritative knowledge base on North Korean DPRK cyber espionage operations for threat intelligence teams and researchers.

Core Features & Use Cases

  • Comprehensive actor profiles (Lazarus Group, APT38, Kimsuky, Andariel) with summaries, campaigns, and known TTPs.
  • Living updates and source references to enable timely situational awareness and historical context.
  • Use cases include threat intelligence research, campaign tracking, risk assessment, and intelligence writing.

Quick Start

Query the DPRK cyber espionage knowledge cell to retrieve current threat actor profiles and campaigns.

Frequently Asked Questions about dprk-cyber-espionage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I track DPRK cyber espionage campaigns and threat actor profiles?

To track DPRK cyber espionage campaigns, query the knowledge cell to retrieve structured metadata, narrative summaries, and versioned updates with source references for actor profiles like Lazarus Group, APT38, Kimsuky, and Andariel.

What North Korean hacker groups are covered in this cyber espionage knowledge base?

The cyber espionage knowledge base covers major North Korean hacker groups, including Lazarus Group, APT38, Kimsuky, and Andariel, providing summaries, known campaigns, and tactics, techniques, and procedures (TTPs).

Can I use this for threat intelligence research in enterprise environments?

Yes, you can use this for threat intelligence research in enterprise environments, as it is designed to support situational awareness, risk assessment, and intelligence writing across both government and enterprise contexts.

Does the DPRK threat actor data include source references for reproducible analysis?

Yes, the DPRK threat actor data includes source references and versioned updates, ensuring that threat intelligence teams can perform reproducible analysis and maintain historical context for situational awareness.

How do I retrieve current TTPs for APT38 and Kimsuky for risk assessment?

To retrieve current TTPs for APT38 and Kimsuky, query the living knowledge cell to access comprehensive actor profiles, structured campaign data, and narrative summaries tailored for risk assessment.