Group123

2018-01-16 • Cisco TalosKorea In The Crosshairs

Group 123 was named by Cisco Talos, which in January 2018 assessed with high confidence that the actor was responsible for six campaigns spanning 2017 into early 2018 against South Korean targets, including operations nicknamed Golden Time, Evil New Year, North Korean Human Rights, FreeMilk, and a disk-wiping campaign called Are You Happy. The group relies on spear-phishing emails, written in fluent Korean, that deliver malicious Hangul Word Processor documents exploiting a known Hangul vulnerability or, against non-Korean financial-sector targets, Microsoft Office documents exploiting a separate known flaw, to install the ROKRAT remote access tool, sometimes staged through additional loader malware. Group 123 has compromised legitimate infrastructure, including a Korean university's mail system and a government legal-services website, to distribute and host lures, and used a ROKRAT-based disk-wiper module. Later reporting, including from Cyfirma, describes the group as active since at least 2012 and tracked under other industry names including APT37, Reaper, and ScarCruft, noting continued espionage against defense, aerospace, and nuclear-related targets alongside ransomware use for funding.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster