국가기반 APT 그룹 '오퍼레이션 스타크루저(Operation Starcruiser)' 수행 … 사이버 첩보활동 지속

2018-04-26 ESTSecurity Country-based APT group carried out ‘Operation Starcruiser'… Cyber ​​espionage activities continue

http://blog.alyac.co.kr/1653

Thumbnail for 국가기반 APT 그룹 '오퍼레이션 스타크루저(Operation Starcruiser)' 수행 … 사이버 첩보활동 지속

ESRC described Operation Star Cruiser as an active spear-phishing campaign against South Korean cryptocurrency-related targets and assessed it as linked to the Lazarus group. The attack used malicious HWP documents tailored to Korean environments, with embedded PostScript and shellcode that downloaded payloads disguised as AVI files such as star3.avi and star6.avi. ESRC connected Star Cruiser to the earlier Battle Cruiser operation through shared TTPs, similar implants, matching C2 protocol elements, overlapping code structure, and related infrastructure paths such as include/left.php. The report is important for DPRK-focused tracking because it links document-exploit delivery, cryptocurrency-sector targeting, and infrastructure reuse to a continuing Lazarus-attributed operational chain.

« Back