the Maiden of Anguish
First seen: 2017-07 •
Last seen: 2026-05
#Sejong • 2018-05
The Sejong Institute incident was a South Korea-focused watering-hole operation against reunification, diplomacy, and security stakeholders, using an ActiveX vulnerability in AcubeFileCtrl.ocx before version 2.3.0.4 to download and execute malware. The injected JavaScript collected browser and ActiveX installation details and sent them to attacker infrastructure, while the malware authenticated to C2, used RC4 with a fixed key, collected host details, and executed commands through cmd.exe.
2
Related Reports
1
Affected Countries
97
Months Since
the Maiden of Anguish