Campaign DOKKAEBI: Documents of Korean and Evil Binary
2018-08-01 • FSI •
Attachments
FSI analyzed known malicious Korean HWP documents from 2015 through the first half of 2018 and grouped related activity into Campaign DOKKAEBI. The excerpt identifies three threat groups using malicious HWP documents in cyberattacks: Bluenoroff, Kimsuky, and Scarcruft. It notes that each group’s document features and follow-on malware differed, while similarities in background, objectives, and attack methods supported treating the activity as a connected set of intrusions. For DPRK-focused tracking, the value is the report’s comparative profiling of HWP-based activity tied to Bluenoroff and Kimsuky alongside Scarcruft.
Related Actors
Related Reports
Shares tags: Kimsuky, Scarcruft, Whitepaper • Same author: FSI
2025-01-20 •
44% Match
An exploratory analysis of the DPRK cyber threat landscape using publicly available reports
lazarusholic
Shares tags: Kimsuky, Scarcruft, Bluenoroff
2024-03-07 •
44% Match
#Andariel
#Kimsuky
#Scarcruft
#Sanctions
#Bluenoroff
#Qubit
#Eterbase
#KuCoin
#Coinrail
#Indodax
#JumpCloud
#bZx
#Alphapo
#CoinsPaid
#CoinEx
#Poloniex
#CyberLink
#HECO
#HTX
#AlgoCapital
#OrbitBridge
#Terraport
#Merlin
#Steadefi
#Fantom
#UnoRe
#NexusMutual
#CoinTiger
#Bondly
#DeFiance
#MGNR
#Fetchai
#EasyFi
#FinNexus
#Cryptopia
#BiKi
#CoinBene
#Gateio
#Bancor
#Tradeio
#CoinSecure
#Taylor
#Cypherium
Shares tags: Kimsuky, Scarcruft, Bluenoroff
Shares tag: Kimsuky • Same author: FSI
Shares tag: Kimsuky
Shares tags: Kimsuky, Scarcruft