the Maiden of Anguish
First seen: 2017-07 •
Last seen: 2026-05
#BLACKSHEEP • 2016-04
BLACKSHEEP is preserved as an Andariel-linked South Korea incident through FSI’s Rifle campaign archive, which grouped BLACKSHEEP with other linked intrusions and malware cases assessed as activity by the same attacker. The available evidence is limited but places the case in a Korea-focused Andariel/Rifle cluster involving malicious-code profiling and Hangul document tradecraft against domestic targets.
1
Related Reports
1
Affected Countries
122
Months Since
the Maiden of Anguish