금성121
2018-05-28 • ESTSecurity • 판문점 선언 관련 내용의 문서로 수행된 '작전명 원제로(Operation Onezero)…
Geumseong121 is a threat group tracked and named by South Korean security firm ESTSecurity (ESRC), which first surfaced the cluster in May 2018 through a Panmunjom Declaration-themed decoy document that overlapped with Kimsuky-related indicators, then explicitly named the group the following July after an email impersonating an inter-Korean separated-families survey. Reports trace the group through named campaigns spanning 2018–2023 and note overlap with aliases used by other vendors for related North Korean activity. Its targeting consistently centers on South Korean government, unification-policy and security researchers, anti-North organizations and activists, North Korean defectors and defector-support groups, and North Korea-focused media, later expanding to political and social-issue lures and messaging-app users. TTPs include spearphishing with exploited office-document formats, fake secure-mail pages, Android spyware distributed via social media, fake charity and community apps, steganography, long-term catfishing via a popular Korean messaging app to build trust before payload delivery, disguised script-based loaders, impersonation of the Ministry of Unification and a mobile payment service, and heavy reliance on cloud storage services for command-and-control and data exfiltration.
-
26
Related Actors
-
284
Related Reports