Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide

2018-04-24 Mcafee

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide/

McAfee attributed Operation GhostSecret with high confidence to Hidden Cobra and described a global data-reconnaissance campaign affecting sectors including critical infrastructure, entertainment, finance, health care, telecommunications, and higher education. The campaign used multiple implants, including a Destover-like variant, Bankshot-related functionality, and the previously undocumented Proxysvc component, with code and PE rich-header overlaps linking them to earlier Hidden Cobra tooling. The Destover-like implant used FakeTLS over port 443 with PolarSSL and control-server traffic similar to Backdoor.Escad, while Proxysvc acted as a covert SSL listener that could support additional implants or infrastructure. Infrastructure findings included active control servers, reused SSL certificates, and ties to servers associated with earlier Sony Pictures-related activity, making the campaign significant for tracking long-lived DPRK-linked tooling and infrastructure reuse.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fe887fcab66d7d7f79f05e0266c0649… 2018-04-24 2023-02-23
IPv4 14.140.116.172 2018-04-24 2020-02-25
HASH 7fe373376e0357624a1d21cd803ce62… 2018-04-24 2018-04-24
HASH 33ffbc8d6850794fa3b7bccb7b1aa12… 2018-04-24 2018-04-24
HASH d0cb9b2d4809575e1bc1f4657e0eb56… 2018-04-24 2018-04-24
HASH 8a7621dba2e88e32c02fe0889d2796a… 2018-04-24 2018-04-24
HASH 8f2918c721511536d8c72144eabaf68… 2018-04-24 2018-04-24
IPv4 121.240.155.78 2018-04-24 2018-04-24
IPv4 203.131.222.83 2018-04-24 2018-04-24
IPv4 121.240.155.77 2018-04-24 2018-04-24
IPv4 223.30.98.170 2018-04-24 2018-04-24
IPv4 223.30.98.169 2018-04-24 2018-04-24
IPv4 203.131.222.109 2018-04-24 2018-04-24
IPv4 121.240.155.76 2018-04-24 2018-04-24
IPv4 121.240.155.74 2018-04-24 2018-04-24
IPv4 193.248.247.59 2018-04-24 2018-04-24
IPv4 196.4.67.45 2018-04-24 2018-04-24

Related Reports

« Back