Datadog Security Labs · Crawled Jul 25, 2026

Stressed Pungsan: DPRK-aligned threat actor leverages npm for initial access | Datadog Security Labs

8 IoCs 1 Actors
Read original article ↗

AI Summary

Stressed Pungsan, a DPRK-aligned threat actor, has been observed leveraging malicious npm packages for initial access. The actor published two packages, 'harthat-hash' and 'harthat-api', which execute a preinstall script to download and run a malicious DLL from a C2 server. The infrastructure and TTPs align with Microsoft's MOONSTONE SLEET, indicating a focus on Windows environments and potential espionage or credential theft objectives.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 8 extracted

Type Value Detail
IP 142[.]111[.]77[.]196 Details →
Package harthat-hash Details →
Package harthat-api Details →
Filename Temp.b Details →
Filename package.db Details →
Filename package.bat Details →
SHA-256 d2a74db6b9c900ad29a81432af72eee8ed4e22bf61055e7e8f7a5f1a33778277 Details →
Registry User nagasiren978 Details →

MITRE ATT&CK TTPs 53 techniques

T1001 Data Obfuscation · Command And Control T1003 OS Credential Dumping · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.004 SSH · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1029 Scheduled Transfer · Exfiltration T1036.005 Match Legitimate Name or Location · Defense Evasion T1040 Network Sniffing · Credential Access T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1057 Process Discovery · Discovery T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1085 T1085 T1087 Account Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1195.002 Compromise Software Supply Chain · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218 System Binary Proxy Execution · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1495 Firmware Corruption · Impact T1534 Internal Spearphishing · Lateral Movement T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1566.002 Spearphishing Link · Initial Access T1583 Acquire Infrastructure · Resource Development T1610 Deploy Container · Defense Evasion