Korea In The Crosshairs

2018-01-16 Cisco Talos

http://blog.talosintelligence.com/2018/01/korea-in-crosshairs.html

Thumbnail for Korea In The Crosshairs

Talos links six 2017-to-early-2018 campaigns to Group 123, with shared code and PDB artifacts tying activity such as Golden Time, Evil New Year, North Korean Human Rights, FreeMilk, and Are You Happy? together. Several campaigns targeted South Korean users through spear phishing and malicious Hancom HWP documents themed around reunification, North Korean human rights, and North Korean New Year topics. The infection chains used HWP and Microsoft Office exploits including CVE-2013-0808 and CVE-2017-0199, OLE objects, downloader stages, and compromised web servers to deliver ROKRAT or related malware such as Freenki and PoohMilk. ROKRAT variants used anti-analysis checks, cloud and social platforms including Twitter, Yandex, and MediaFire for command and exfiltration, while the Are You Happy? activity showed a destructive ROKRAT wiper module. The evidence matters because it shows a Korean-focused actor evolving from spear-phishing RAT delivery into multi-stage, cloud-backed, and destructive operations against South Korean interests.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b3de3f9309b2f320738772353eb724a… 2018-01-16 2025-04-01
HASH 9b383ebc1c592d5556fec9d513223d4… 2018-01-16 2020-03-09
HASH a29b07a6fe5d7ce3147dd7ef1d7d18d… 2018-01-16 2020-03-09
DOMAIN acddesigns.com.au 2016-11-18 2019-05-14
HASH 99c1b4887d96cb94f32b280c1039b3a… 2017-10-05 2018-10-03
HASH 7f35521cdbaa4e86143656ff9c52cef… 2017-10-05 2018-10-03
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
DOMAIN old.jrchina.com 2017-10-05 2018-03-23
HASH 7ebc9a1fd93525fc42277efbccecf5a… 2017-02-23 2018-02-27
HASH 7d8008028488edd26e665a3d4f70576… 2017-02-23 2018-02-27
HASH 6c372f29615ce8ae2cdf257e9f26178… 2017-02-23 2018-02-27
HASH 95192de1f3239d5c0a7075627cf9845… 2017-02-23 2018-02-27
HASH 19e4c45c0cd992564532b89a4dc1f35… 2017-02-23 2018-02-27
HASH a585849d02c94e93022c5257b162f74… 2018-01-16 2018-01-16
HASH 6332c97c76d2da7101ad05f501dc118… 2018-01-16 2018-01-16
HASH 3f7827bf26150ec26c61d8dbf43cdb8… 2018-01-16 2018-01-16
HASH bdd48dbed10f74f234ed38908756b5c… 2018-01-16 2018-01-16
HASH f1419cde4dd4e1785d6ec6d33afb413… 2018-01-16 2018-01-16
HASH f068196d2c492b49e4aae4312c140e9… 2018-01-16 2018-01-16
HASH 171e26822421f7ed2e34cc092eaeba8… 2018-01-16 2018-01-16
HASH eb6d25e08b2b32a736b57f8df22db6d… 2018-01-16 2018-01-16
URL http://60chicken.co.kr/wysiwyg/… 2018-01-16 2018-01-16
URL http://old.jrchina.com/btob_asi… 2018-01-16 2018-01-16
DOMAIN 60chicken.co.kr 2018-01-04 2018-01-16
HASH 35273d6c25665a19ac14d469e143622… 2017-10-05 2018-01-16
HASH 1893af524edea4541c317df288adbf1… 2017-10-05 2018-01-16
HASH 051463a14767c6477b6dacd639f30a8… 2017-04-03 2018-01-16
HASH 7d163e36f47ec56c9fe08d758a0770f… 2017-04-03 2018-01-16
HASH cd166565ce09ef410c5bba40bad0b49… 2017-04-03 2018-01-16
HASH 5441f45df22af63498c63a49aae8206… 2017-04-03 2018-01-16
URL http://acddesigns.com.au/client… 2017-04-03 2018-01-16
URL http://discgolfglow.com/wp-cont… 2017-04-03 2018-01-16
URL http://discgolfglow.com:/wp-con… 2017-04-03 2018-01-16
DOMAIN discgolfglow.com 2017-04-03 2018-01-16
HASH 3d442c4457cf921b7a335c0d7276bea… 2017-02-23 2018-01-16
HASH 281828d6f5bd377f91c6283c34896d0… 2017-02-23 2018-01-16
HASH 761454dafba7e191587735c0dc5c6c8… 2017-02-23 2018-01-16
HASH 3a0fc4cc145eafe20129e9c53aac424… 2017-02-23 2018-01-16
HASH 7e810cb159fab5baccee7e72708d974… 2017-02-23 2018-01-16
HASH f080f019073654acbe6b7ab735d3fd2… 2017-02-23 2018-01-16
HASH 21b098d721ea88bf237c08cdb5c619a… 2017-02-23 2018-01-16
HASH 930fce7272ede29833abbfb5df4e32e… 2017-02-23 2018-01-16
HASH 4b20883386665bd205ac50f34f7b629… 2017-02-23 2018-01-16

Related Actors

Related Reports

« Back