Attacks Leveraging Adobe Zero-Day (CVE-2018-4878)

2018-02-03 Mandiant

https://www.mandiant.com/resources/blog/attacks-leveraging-adobe-zero-day-cve-2018-4878-threat-attribution-attack-scenario-and-recommendations-blog

Thumbnail for Attacks Leveraging Adobe Zero-Day (CVE-2018-4878)

FireEye assessed that exploitation of Adobe Flash zero-day CVE-2018-4878 was being carried out by TEMP.Reaper, a suspected North Korean group. The actor had historically focused on South Korean government, military, and defense targets, with interest in Korean unification and North Korean defectors, and had expanded to international targeting. The exploit chain involved malicious documents or spreadsheets with an embedded SWF file, retrieving a decryption key from compromised South Korean websites to unlock an embedded payload. Preliminary analysis indicated the vulnerability was likely used to distribute DOGCALL malware to South Korean victims, while FireEye also noted previously observed TEMP.Reaper wiper malware tracked as RUHAPPY but no active use against targets at that time.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 28.0.0.137 2018-02-02 2018-03-14

Related Actors

Related Reports

« Back