Shares tag: BookCodes • Same author: KRCERT • Published within a month
Operation Bookcodes – targeting South Korea
2021-11-04 • KRCERT •
KISA's Operation Bookcodes presentation describes a campaign that began in April 2019 against South Korean maritime, media, and security software targets. The attackers used malicious HWP documents and phishing links to install remote control malware, then downloaded droppers and registered launchers for persistence. The transcript also describes C2 infrastructure, target IP checks before payload delivery, encrypted server address files, and follow-on malware used to collect host data and maintain control.
Related Reports
Shares tag: Youtube • Published within a week
2021-10-09 •
40% Match
Multi-universe of adversary: multiple campaigns of the Lazarus group and their connections
Kaspersky
Shares tag: Youtube • Published within a month
Shares tag: Youtube • Same author: KRCERT
Shares tag: BookCodes • Same author: KRCERT
2021-09-08 •
30% Match
Bitcoin is silver, compromise is gold: Emerging North Korea-based threat actors on the hunt for cryptocurrency
PWC
Shares tag: Youtube