오퍼레이션 블랙버드(Operation Blackbird)', 금성121의 모바일 침공

2018-12-13 ESTSecurity ‘Operation Blackbird', Venus 121's mobile invasion

http://blog.alyac.co.kr/2035

Thumbnail for 오퍼레이션 블랙버드(Operation Blackbird)', 금성121의 모바일 침공

ESRC attributes Operation Blackbird activity to the suspected Geumseong 121 group and shows the operation expanding from earlier server and PC targeting into Android mobile espionage. The campaign targeted North Korean defectors and related individuals by sending direct app-install links through SNS comments or messengers such as KakaoTalk, indicating a narrowed, targeted delivery model rather than mass malware distribution. The spyware history includes droppers that abused Samsung and LG device vulnerabilities, including CVE-2015-7888, and later apps disguised as useful software to persuade victims to install them. The apps registered device details, downloaded command files and additional DEX modules, collected sensitive data including account and document information, and exfiltrated encrypted results to Dropbox, Yandex, or compromised web servers. Dropbox folders tied to the operation reportedly exposed attacker test data, suspected operator email and KakaoTalk profile information, exploit code, and victim personal data, giving defenders infrastructure and behavioral evidence to track the activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 948f1d50d1784908ece778614315a995 2018-12-13 2018-12-13
HASH 19a06965edc7b86f7b63d5a86b927a87 2018-12-13 2018-12-13

Related Actors

Related Reports

« Back