금성121 그룹의 최신 APT 캠페인 - '작전명 로켓 맨(Operation Rocket Man)'
2018-08-22 • ESTSecurity • Geumseong121 Group's latest APT campaign - 'Operation Rocket Man' •
ESRC describes Operation Rocket Man, activity attributed in the excerpt to the Geumseong121 group, which has targeted South Korean North Korea-related organizations and defense-sector entities. The August 2018 case used spear phishing in which attackers impersonated a South Korean corporate HR employee and linked to compromised Korean web infrastructure instead of attaching the lure directly. The malware posed as a PC security program, installed additional components in stages, and used .NET version-dependent execution with PDB paths referencing Ant and Rocket project directories. Configuration data was downloaded as an encrypted desktops.ini file, decrypted with XOR 0x17, and used to communicate through PubNub command-and-control channels; the excerpt also lists delivery and payload URLs under m.ssbw.co.kr. ESRC connects the tooling and infrastructure to earlier campaigns using HWP documents, cloud services, endlesspaws.com, and false-flag Chinese-language artifacts intended to confuse threat intelligence analysis.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 84cbbb8cdad90fba8b964297dd5c648a | 2018-08-22 | 2018-08-22 |
| HASH | edc1bdb2d70e36891826fdd58682b6c4 | 2018-08-22 | 2018-08-22 |
| HASH | b710e5a4ca00a52f6297a3cc7190393a | 2018-08-22 | 2018-08-22 |
| HASH | 05eef00de73498167b2d7ebdc492c429 | 2018-08-22 | 2018-08-22 |
| HASH | af6721145079a05da53c8d0f3656c65c | 2018-08-22 | 2018-08-22 |
| HASH | ff32383f207b6cdd8ab6cbcba26b1430 | 2018-08-22 | 2018-08-22 |
| HASH | ab2a4537c9d6761b36ae8935d1e5ed8a | 2018-08-22 | 2018-08-22 |
| HASH | fa39b3b422dc4232ef24e3f27fa8d69e | 2018-08-22 | 2018-08-22 |
| HASH | 8ab2819e42a1556ba81be914d6c3021f | 2018-08-22 | 2018-08-22 |
| HASH | 1213e5a0be1fbd9a7103ab08fe8ea5cb | 2018-08-22 | 2018-08-22 |
| HASH | 24fe3fb56a61aad6d28ccc58f283017c | 2018-08-22 | 2018-08-22 |
| HASH | 9525c314ecbee7818ba9a819edb4a885 | 2018-08-22 | 2018-08-22 |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| [email protected] | 2018-08-22 | 2018-08-22 | |
| URL | http://m.ssbw.co.kr/admin/form_… | 2018-08-22 | 2018-08-22 |
| URL | http://cgalim.com/admin/hr/temp… | 2018-08-22 | 2018-08-22 |
| URL | http://m.ssbw.co.kr/admin/form_… | 2018-08-22 | 2018-08-22 |
| URL | http://endlesspaws.com/vog/denk… | 2018-08-22 | 2018-08-22 |
| URL | http://m.ssbw.co.kr/admin/form_… | 2018-08-22 | 2018-08-22 |
| URL | http://m.ssbw.co.kr/admin/form_… | 2018-08-22 | 2018-08-22 |
| URL | http://m.ssbw.co.kr/admin/form_… | 2018-08-22 | 2018-08-22 |
| URL | http://ebsmpi.com/ipin/360/down… | 2018-08-22 | 2018-08-22 |
| URL | http://endlesspaws.com/vog/tan.… | 2018-08-22 | 2018-08-22 |
| DOMAIN | seline.co.kr | 2018-08-22 | 2018-08-22 |
| DOMAIN | m.ssbw.co.kr | 2018-08-22 | 2018-08-22 |
| DOMAIN | streamnation.com | 2018-08-22 | 2018-08-22 |
| DOMAIN | zmail.ru | 2018-08-22 | 2018-08-22 |
| DOMAIN | cnjob.co.kr | 2018-08-22 | 2018-08-22 |
| DOMAIN | inbox.com | 2018-08-22 | 2018-08-22 |
| DOMAIN | notac.co.kr | 2018-08-22 | 2018-08-22 |
| IPv4 | 175.45.178.133 | 2018-08-22 | 2018-08-22 |
| URL | http://ebsmpi.com/ipin/360/desk… | 2018-04-02 | 2018-08-22 |
| URL | http://ebsmpi.com/ipin/360/Ant_… | 2018-04-02 | 2018-08-22 |
| URL | http://cgalim.com/admin/hr/1.apk | 2018-04-02 | 2018-08-22 |
| URL | http://cgalim.com/admin/hr/hr.d… | 2018-04-02 | 2018-08-22 |
| URL | http://ebsmpi.com/ipin/360/Ant_… | 2018-04-02 | 2018-08-22 |
| DOMAIN | ebsmpi.com | 2018-04-02 | 2018-08-22 |
| DOMAIN | cgalim.com | 2018-04-02 | 2018-08-22 |
| DOMAIN | endlesspaws.com | 2018-03-05 | 2018-08-22 |