Detailed Analysis of Red Eyes Hacking Group

2018-08-14 Ahnlab

https://global.ahnlab.com/global/upload/download/techreport/[AhnLab]%20Red_Eyes_Hacking_Group_Report%20(1).pdf

Attachments

AhnLab20Red_Eyes_Hacking_Group_Report201.pdf (918 KB)

AhnLab links Red Eyes to Geumseong121, Group 123, ScarCruft, APT37, Reaper, and Ricochet Chollima, with repeated targeting of people and organizations working on North Korea. The activity focused on North Korean defectors, human rights activists, researchers, journalists, and in some cases Korean military-related documents. The group delivered malware through documents sent by email or mobile messenger, embedding VBS or executable payloads and exploiting Hangul EPS issues, Microsoft Word DDE, and Adobe Flash CVE-2018-4878. Observed malware included document files, droppers, and backdoors such as DocPrint/Reloader and DogCall/Redoor, with PDB paths showing recurring development strings across samples.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7ca1e08fc07166a440576d1af0a15bb1 2018-04-03 2023-05-23
HASH 44bdeb6c0af7c36a08c64e31ceadc63c 2018-04-03 2023-05-23
HASH 6cec7de9d4797895775e2add9d6855ba 2018-04-03 2018-08-14
HASH 9cd11aa7872f9cba98264113d3d72893 2018-04-03 2018-08-14
HASH f793deeee9dc4235d228e68d27057dcc 2018-04-03 2018-08-14
HASH 89c3254aa577d3788f0f402fe6e5a855 2018-04-03 2018-08-14
HASH 8b55d52b12cf319d9785ad8eeeade5ea 2018-04-03 2018-08-14
HASH 9f1e60e0c794aa3f3bdf8a6645ccabdc 2018-04-03 2018-08-14
HASH f0a5385d0d9f7c546b25a7448ca5b1c9 2018-04-03 2018-08-14
HASH 2f0492f53d348bea993b7ae5983508a6 2018-04-03 2018-08-14
HASH 06ae5d62d56f21cd2676989743b9626c 2018-04-03 2018-08-14
HASH 2fdbb9a500143a2dd3d226a1cc3e45b5 2018-04-03 2018-08-14
HASH 49d30adaab769fbea2ef69e09c6598c5 2018-04-03 2018-08-14
HASH 9ac2ffd3f1cea2e01ed77c2e7b4a29e7 2018-04-03 2018-08-14
HASH d00e3196bc847e63fc4b255e8ab06d1c 2018-04-03 2018-08-14
HASH f613c9276d0deb19d0959aa2fbfc737c 2018-04-03 2018-08-14
DOMAIN byline.network 2018-04-03 2018-08-14
DOMAIN ush.co.kr 2018-04-03 2018-08-14
HASH 0ff0f3f0722dd122a0f5c3d4c7752675 2018-02-27 2018-08-14
HASH fc0a9850f7b6a91f7757d64c86cfc141 2018-02-27 2018-08-14

Related Actors

Related Reports

« Back