금성121 그룹의 최신 APT 캠페인 - '작전명 로켓 맨(Operation Rocket Man)'

2018-08-22 ESTSecurity Geumseong121 Group's latest APT campaign - 'Operation Rocket Man'

http://blog.alyac.co.kr/1853

Thumbnail for 금성121 그룹의 최신 APT 캠페인 - '작전명 로켓 맨(Operation Rocket Man)'

ESRC describes Operation Rocket Man, activity attributed in the excerpt to the Geumseong121 group, which has targeted South Korean North Korea-related organizations and defense-sector entities. The August 2018 case used spear phishing in which attackers impersonated a South Korean corporate HR employee and linked to compromised Korean web infrastructure instead of attaching the lure directly. The malware posed as a PC security program, installed additional components in stages, and used .NET version-dependent execution with PDB paths referencing Ant and Rocket project directories. Configuration data was downloaded as an encrypted desktops.ini file, decrypted with XOR 0x17, and used to communicate through PubNub command-and-control channels; the excerpt also lists delivery and payload URLs under m.ssbw.co.kr. ESRC connects the tooling and infrastructure to earlier campaigns using HWP documents, cloud services, endlesspaws.com, and false-flag Chinese-language artifacts intended to confuse threat intelligence analysis.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 84cbbb8cdad90fba8b964297dd5c648a 2018-08-22 2018-08-22
HASH edc1bdb2d70e36891826fdd58682b6c4 2018-08-22 2018-08-22
HASH b710e5a4ca00a52f6297a3cc7190393a 2018-08-22 2018-08-22
HASH 05eef00de73498167b2d7ebdc492c429 2018-08-22 2018-08-22
HASH af6721145079a05da53c8d0f3656c65c 2018-08-22 2018-08-22
HASH ff32383f207b6cdd8ab6cbcba26b1430 2018-08-22 2018-08-22
HASH ab2a4537c9d6761b36ae8935d1e5ed8a 2018-08-22 2018-08-22
HASH fa39b3b422dc4232ef24e3f27fa8d69e 2018-08-22 2018-08-22
HASH 8ab2819e42a1556ba81be914d6c3021f 2018-08-22 2018-08-22
HASH 1213e5a0be1fbd9a7103ab08fe8ea5cb 2018-08-22 2018-08-22
HASH 24fe3fb56a61aad6d28ccc58f283017c 2018-08-22 2018-08-22
HASH 9525c314ecbee7818ba9a819edb4a885 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
EMAIL [email protected] 2018-08-22 2018-08-22
URL http://m.ssbw.co.kr/admin/form_… 2018-08-22 2018-08-22
URL http://cgalim.com/admin/hr/temp… 2018-08-22 2018-08-22
URL http://m.ssbw.co.kr/admin/form_… 2018-08-22 2018-08-22
URL http://endlesspaws.com/vog/denk… 2018-08-22 2018-08-22
URL http://m.ssbw.co.kr/admin/form_… 2018-08-22 2018-08-22
URL http://m.ssbw.co.kr/admin/form_… 2018-08-22 2018-08-22
URL http://m.ssbw.co.kr/admin/form_… 2018-08-22 2018-08-22
URL http://ebsmpi.com/ipin/360/down… 2018-08-22 2018-08-22
URL http://endlesspaws.com/vog/tan.… 2018-08-22 2018-08-22
DOMAIN seline.co.kr 2018-08-22 2018-08-22
DOMAIN m.ssbw.co.kr 2018-08-22 2018-08-22
DOMAIN streamnation.com 2018-08-22 2018-08-22
DOMAIN zmail.ru 2018-08-22 2018-08-22
DOMAIN cnjob.co.kr 2018-08-22 2018-08-22
DOMAIN inbox.com 2018-08-22 2018-08-22
DOMAIN notac.co.kr 2018-08-22 2018-08-22
IPv4 175.45.178.133 2018-08-22 2018-08-22
URL http://ebsmpi.com/ipin/360/desk… 2018-04-02 2018-08-22
URL http://ebsmpi.com/ipin/360/Ant_… 2018-04-02 2018-08-22
URL http://cgalim.com/admin/hr/1.apk 2018-04-02 2018-08-22
URL http://cgalim.com/admin/hr/hr.d… 2018-04-02 2018-08-22
URL http://ebsmpi.com/ipin/360/Ant_… 2018-04-02 2018-08-22
DOMAIN ebsmpi.com 2018-04-02 2018-08-22
DOMAIN cgalim.com 2018-04-02 2018-08-22
DOMAIN endlesspaws.com 2018-03-05 2018-08-22

Related Actors

Related Reports

« Back