Operation GoldenAxe

2017-05-15 Issuemakers Lab

http://taylor-blog.issuemakerslab.com/2018/07/operation-goldenaxe.html

Thumbnail for Operation GoldenAxe

Operation GoldenAxe describes suspected North Korean activity from June 2016 to May 2017 that compromised more than ten South Korean organization websites tied to diplomacy, aviation, North Korea affairs, unification, parliament, labor, and finance. The attackers used compromised association and institutional websites as watering-hole distribution points, exploiting zero-day vulnerabilities in widely deployed South Korean ActiveX programs for payments, authentication, encryption, reporting, webmail, and groupware. The distributed malware enabled remote control, information theft, and additional payload delivery, and the excerpt says its encryption logic, protocol elements, and C2 command system overlapped with malware previously attributed by South Korean police and prosecutors to North Korea. The report also links the activity to earlier South Korean ATM hacking suspicions and the 2013 March 20 broadcast and financial attacks, highlighting ActiveX software as a recurring weakness in North Korea-linked intrusion chains against South Korean targets.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://www.ksas.or.kr 2017-05-15 2017-05-15
URL http://www.wblu.or.kr 2017-05-15 2017-05-15
URL http://www.rokps.or.kr 2017-05-15 2017-05-15
URL http://www.tongiledu.org 2017-05-15 2017-05-15
URL http://kuprp.nodong.net 2017-05-15 2017-05-15
URL http://www.tongzun.co.kr 2017-05-15 2017-05-15
URL http://www.nksis.com 2017-05-15 2017-05-15
DOMAIN kuprp.nodong.net 2017-05-15 2017-05-15

Related Reports

« Back