Operation Kabar Cobra: Kimsuky 공격 그룹의 최신 타깃 공격 사례 분석
2019-03-04 • Ahnlab • Operation Kabar Cobra: Analysis of the latest targeted attacks by the Kimsuky attack group •
http://download.ahnlab.com/kr/site/library/[Analysis_Report]Operation_Kabar_Cobra.pdf
Attachments
AhnLab attributes Operation Kabar Cobra to activity suspected of being linked to Kimsuky, including January 2019 malware sent to Ministry of Unification reporters and other recent targeting of military, media, finance, cryptocurrency, and related sectors. The attacks used files disguised as Hangul documents with double extensions and long spaces, often packed as WinRAR SFX archives containing decoy HWP/PDF content and malicious WSF scripts. The scripts retrieved C2 configuration from the attacker’s Google Drive, downloaded additional malware such as Freedom.dll/AhnLabMon.dll and list.dll/Cobra.dll, and supported command execution, file transfer, updates, and log transmission with Base64-encoded C2 traffic. Cobra.dll collected drive, hardware, folder, and file-list information and sent it to C2, enabling data theft from real targets or anti-analysis actions when the attacker recognized a research environment. The report is important because it documents Kimsuky-linked adaptation around the U.S.–North Korea summit period and shows flexible C2 management, targeted decoys, and hands-on operator commands.