APT-C-28
2019-06-01 • Qihoo360 • APT-C-28疑似针对韩国电子制造行业的攻击活动
APT-C-28 is Qihoo 360's designation for a Northeast Asian espionage group that the company was publicly tracking under that label by April 2023. Its activity is described as reaching back to at least 2012 and remaining active through 2025, with a strong focus on South Korea and other Asian countries. Reported targets include government personnel and organizations in the chemical, electronics, manufacturing, aerospace, automotive, and healthcare sectors, while the principal objective is theft of strategic military, political, economic, and other sensitive information. Operations use tailored phishing themes and malicious documents or shortcut files to launch scripts, evade privilege controls, establish persistence, and deploy remote-access malware. Later campaigns increasingly centered on RokRat: encrypted payloads were first fetched from cloud services, then embedded directly in shortcut files and decrypted in memory, reflecting adaptation to faster blocking of malicious cloud links while preserving long-term surveillance and data theft.
-
26
Related Actors
-
284
Related Reports