오퍼레이션 레드 갬블러의 실체
2018-06-29 • Ahnlab • The reality of Operation Red Gambler •
http://image.ahnlab.com/file_upload/asecissue_files/ASEC%20REPORT_vol.91.pdf
Attachments
ASEC20REPORT_vol.91.pdf (3 MB)
AhnLab’s ASEC Report Vol.91 describes Operation Red Gambler, a campaign tracked from October 2016 to August 2017 in which a Korea-focused hacking group referred to as “Group A” distributed malware to steal information from domestic Go-Stop and poker-style web-board game users. The activity shifted from earlier institution- and company-focused operations toward financially motivated attacks against ordinary users, abusing modified utility-software installers, lookalike download links, and later PC-café management environments to deliver malware. The malware bypassed UAC through `mscfile` registry hijacking and `eventvwr.exe`, dropped `taskeng.exe` and `wrmk.dll`, injected into targeted game processes with `SetWindowsHookExA`, captured game-room and screen data through memory-hacking routines, and sent encrypted data to C&C servers for use in gambling fraud. ASEC linked the campaign to prior Korea-focused attacks through shared encryption/decryption code patterns, while naming the actor only as “Group A” rather than directly attributing it to Lazarus or DPRK in this section.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | hopto.org | 2018-06-29 | 2025-05-27 |
| HASH | 9a50be3def3681242f35d3c0911e2e70 | 2018-06-29 | 2020-03-09 |
| HASH | 323a410779f2aef79a5e1e0ee600789d | 2018-06-29 | 2018-06-29 |
| HASH | 0bba3d00a4212d24b4c77bb06efcee47 | 2018-06-29 | 2018-06-29 |
| HASH | c8c14063031059c724c2a4f5ed0898df | 2018-06-29 | 2018-06-29 |
| HASH | 40f4305b7c9bf1236b9accbc0dc8fb88 | 2018-06-29 | 2018-06-29 |
| HASH | 7f007fd794c93267f57cabe464dbdc5a | 2018-06-29 | 2018-06-29 |
| HASH | 2573d0ad00f4ba8ee86d7fce7454d963 | 2018-06-29 | 2018-06-29 |
| HASH | a59dab67bf24d3d5e139b5f5611a6cfe | 2018-06-29 | 2018-06-29 |
| HASH | ffe1401330a8fee59bcc058ecac0ed18 | 2018-06-29 | 2018-06-29 |
| HASH | 768bd6497d7e903d28120b1152feced1 | 2018-06-29 | 2018-06-29 |
| HASH | de372dba210fad421d92e8298164a22d | 2018-06-29 | 2018-06-29 |
| DOMAIN | tory1.com | 2018-06-29 | 2018-06-29 |
| DOMAIN | ware.co.kr | 2018-06-29 | 2018-06-29 |
| DOMAIN | p.com | 2018-06-29 | 2018-06-29 |
| DOMAIN | named.ddns.net | 2018-06-29 | 2018-06-29 |
| DOMAIN | pmang.servegame.com | 2018-06-29 | 2018-06-29 |
| DOMAIN | tory.com | 2018-06-29 | 2018-06-29 |
| DOMAIN | daum.servehttp.com | 2018-06-29 | 2018-06-29 |
| DOMAIN | naver.serveblog.net | 2018-06-29 | 2018-06-29 |
| DOMAIN | neowiz.servegame.com | 2018-06-29 | 2018-06-29 |
| DOMAIN | blogs.pgafan.net | 2018-06-29 | 2018-06-29 |
| DOMAIN | mobile.read-books.org | 2018-06-29 | 2018-06-29 |