오퍼레이션 레드 갬블러의 실체

2018-06-29 Ahnlab The reality of Operation Red Gambler

http://image.ahnlab.com/file_upload/asecissue_files/ASEC%20REPORT_vol.91.pdf

Attachments

ASEC20REPORT_vol.91.pdf (3 MB)

Thumbnail for 오퍼레이션 레드 갬블러의 실체

AhnLab’s ASEC Report Vol.91 describes Operation Red Gambler, a campaign tracked from October 2016 to August 2017 in which a Korea-focused hacking group referred to as “Group A” distributed malware to steal information from domestic Go-Stop and poker-style web-board game users. The activity shifted from earlier institution- and company-focused operations toward financially motivated attacks against ordinary users, abusing modified utility-software installers, lookalike download links, and later PC-café management environments to deliver malware. The malware bypassed UAC through `mscfile` registry hijacking and `eventvwr.exe`, dropped `taskeng.exe` and `wrmk.dll`, injected into targeted game processes with `SetWindowsHookExA`, captured game-room and screen data through memory-hacking routines, and sent encrypted data to C&C servers for use in gambling fraud. ASEC linked the campaign to prior Korea-focused attacks through shared encryption/decryption code patterns, while naming the actor only as “Group A” rather than directly attributing it to Lazarus or DPRK in this section.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hopto.org 2018-06-29 2025-05-27
HASH 9a50be3def3681242f35d3c0911e2e70 2018-06-29 2020-03-09
HASH 323a410779f2aef79a5e1e0ee600789d 2018-06-29 2018-06-29
HASH 0bba3d00a4212d24b4c77bb06efcee47 2018-06-29 2018-06-29
HASH c8c14063031059c724c2a4f5ed0898df 2018-06-29 2018-06-29
HASH 40f4305b7c9bf1236b9accbc0dc8fb88 2018-06-29 2018-06-29
HASH 7f007fd794c93267f57cabe464dbdc5a 2018-06-29 2018-06-29
HASH 2573d0ad00f4ba8ee86d7fce7454d963 2018-06-29 2018-06-29
HASH a59dab67bf24d3d5e139b5f5611a6cfe 2018-06-29 2018-06-29
HASH ffe1401330a8fee59bcc058ecac0ed18 2018-06-29 2018-06-29
HASH 768bd6497d7e903d28120b1152feced1 2018-06-29 2018-06-29
HASH de372dba210fad421d92e8298164a22d 2018-06-29 2018-06-29
DOMAIN tory1.com 2018-06-29 2018-06-29
DOMAIN ware.co.kr 2018-06-29 2018-06-29
DOMAIN p.com 2018-06-29 2018-06-29
DOMAIN named.ddns.net 2018-06-29 2018-06-29
DOMAIN pmang.servegame.com 2018-06-29 2018-06-29
DOMAIN tory.com 2018-06-29 2018-06-29
DOMAIN daum.servehttp.com 2018-06-29 2018-06-29
DOMAIN naver.serveblog.net 2018-06-29 2018-06-29
DOMAIN neowiz.servegame.com 2018-06-29 2018-06-29
DOMAIN blogs.pgafan.net 2018-06-29 2018-06-29
DOMAIN mobile.read-books.org 2018-06-29 2018-06-29

Related Reports

« Back