APT-Q-3
2022-03-23 • Qianxin • Group123(APT-Q-3)
Qianxin's Red Drip Team assigned the internal tracking designator APT-Q-3 to the group it tracks as Group123, an espionage-motivated threat actor believed active since 2012 and linked to earlier reported operations known as Operation Daybreak and Operation Erebus. The group initially focused on South Korean targets before expanding after 2017 to Japan, Vietnam, and the Middle East, striking chemical, electronics, manufacturing, aerospace, automotive, and healthcare organizations, and later also government, defense-policy, and diplomatic targets. It relies on tailored spear-phishing lures, including compressed archives containing disguised shortcut (LNK) files, Hangul Word Processor documents, and PDF or audio decoys referencing Korean political and defense events, that drop malicious RTF and PowerShell chains ultimately deploying the RokRAT backdoor, which abuses cloud storage services such as OneDrive, Dropbox, Box, and Yandex for command-and-control and can capture screenshots, log keystrokes, and evade virtual machines. Analysts have separately noted feature overlap between this group and the Kimsuky cluster.
-
26
Related Actors
-
284
Related Reports