Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide
2018-04-24 • Mcafee •
McAfee attributed Operation GhostSecret with high confidence to Hidden Cobra and described a global data-reconnaissance campaign affecting sectors including critical infrastructure, entertainment, finance, health care, telecommunications, and higher education. The campaign used multiple implants, including a Destover-like variant, Bankshot-related functionality, and the previously undocumented Proxysvc component, with code and PE rich-header overlaps linking them to earlier Hidden Cobra tooling. The Destover-like implant used FakeTLS over port 443 with PolarSSL and control-server traffic similar to Backdoor.Escad, while Proxysvc acted as a covert SSL listener that could support additional implants or infrastructure. Infrastructure findings included active control servers, reused SSL certificates, and ties to servers associated with earlier Sony Pictures-related activity, making the campaign significant for tracking long-lived DPRK-linked tooling and infrastructure reuse.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fe887fcab66d7d7f79f05e0266c0649… | 2018-04-24 | 2023-02-23 |
| IPv4 | 14.140.116.172 | 2018-04-24 | 2020-02-25 |
| HASH | 7fe373376e0357624a1d21cd803ce62… | 2018-04-24 | 2018-04-24 |
| HASH | 33ffbc8d6850794fa3b7bccb7b1aa12… | 2018-04-24 | 2018-04-24 |
| HASH | d0cb9b2d4809575e1bc1f4657e0eb56… | 2018-04-24 | 2018-04-24 |
| HASH | 8a7621dba2e88e32c02fe0889d2796a… | 2018-04-24 | 2018-04-24 |
| HASH | 8f2918c721511536d8c72144eabaf68… | 2018-04-24 | 2018-04-24 |
| IPv4 | 121.240.155.78 | 2018-04-24 | 2018-04-24 |
| IPv4 | 203.131.222.83 | 2018-04-24 | 2018-04-24 |
| IPv4 | 121.240.155.77 | 2018-04-24 | 2018-04-24 |
| IPv4 | 223.30.98.170 | 2018-04-24 | 2018-04-24 |
| IPv4 | 223.30.98.169 | 2018-04-24 | 2018-04-24 |
| IPv4 | 203.131.222.109 | 2018-04-24 | 2018-04-24 |
| IPv4 | 121.240.155.76 | 2018-04-24 | 2018-04-24 |
| IPv4 | 121.240.155.74 | 2018-04-24 | 2018-04-24 |
| IPv4 | 193.248.247.59 | 2018-04-24 | 2018-04-24 |
| IPv4 | 196.4.67.45 | 2018-04-24 | 2018-04-24 |