Targeted Attacks Against South Korean Entities May Have Been as Early as November 2017
2018-02-02 • Flashpoint-intel •
https://www.flashpoint-intel.com/blog/targeted-attacks-south-korean-entities/
Flashpoint’s excerpt is a vulnerability prioritization briefing for the week of December 20–26, 2025, focused on remotely exploitable issues with public exploits and available fixes. The highlighted items include NVIDIA Isaac Launchable hardcoded credentials and improper execution privileges issues, n8n workflow expression evaluation remote code execution, and MongoDB Zlib compressed protocol header handling that can disclose uninitialized heap memory. The report explains Flashpoint scoring inputs such as analyst-adjusted CVSS, social risk, ransomware-likelihood similarity, exploit references, affected products, solution data, and exposure metrics. No North Korea, Lazarus, Kimsuky, Andariel, APT37, or APT38 activity is supported by the provided excerpt, so it should be treated as general vulnerability intelligence rather than DPRK-attributed CTI.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 28.0.0.137 | 2018-02-02 | 2018-03-14 |
| YARA | crime_ole_loadswf_cve_2018_4878 | 2018-02-02 | 2018-02-02 |
| HASH | 9593d277b42947ef28217325bcc1fe50 | 2018-02-02 | 2018-02-02 |
| HASH | 4c1533cbfb693da14e54e5a92ce6faba | 2018-02-02 | 2018-02-02 |
| HASH | 5f97c5ea28c0401abc093069a50aa1f8 | 2018-02-02 | 2018-02-02 |
| HASH | 1f93c09eed6bb17ec46e63f00bd40ebb | 2018-02-02 | 2018-02-02 |
| URL | http://www.1588-2040.co.kr/desi… | 2018-02-02 | 2018-02-02 |
| URL | http://www.dylboiler.co.kr/admi… | 2018-02-02 | 2018-02-02 |