오퍼레이션 블랙버드(Operation Blackbird)', 금성121의 모바일 침공
2018-12-13 • ESTSecurity • ‘Operation Blackbird', Venus 121's mobile invasion •
ESRC attributes Operation Blackbird activity to the suspected Geumseong 121 group and shows the operation expanding from earlier server and PC targeting into Android mobile espionage. The campaign targeted North Korean defectors and related individuals by sending direct app-install links through SNS comments or messengers such as KakaoTalk, indicating a narrowed, targeted delivery model rather than mass malware distribution. The spyware history includes droppers that abused Samsung and LG device vulnerabilities, including CVE-2015-7888, and later apps disguised as useful software to persuade victims to install them. The apps registered device details, downloaded command files and additional DEX modules, collected sensitive data including account and document information, and exfiltrated encrypted results to Dropbox, Yandex, or compromised web servers. Dropbox folders tied to the operation reportedly exposed attacker test data, suspected operator email and KakaoTalk profile information, exploit code, and victim personal data, giving defenders infrastructure and behavioral evidence to track the activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 948f1d50d1784908ece778614315a995 | 2018-12-13 | 2018-12-13 |
| HASH | 19a06965edc7b86f7b63d5a86b927a87 | 2018-12-13 | 2018-12-13 |