Red Eyes
2018-03-05 • Ahnlab • https://twitter.com/mstoned7/status/966126706107953152
RedEyes is a name AhnLab's security response center uses for a North Korean-linked hacking group it began documenting in March 2018, based on a sixteen-month study of malicious Hangul Word Processor documents collected between September 2016 and December 2017, in which the group, internally labeled Group A, was found responsible for roughly a quarter of the malicious samples. AhnLab treats RedEyes as the same group publicly reported elsewhere as Geumseong121, Group123, ScarCruft, APT37, Reaper, and Ricochet Chollima, tracing its activity back at least five years and noting possible ties to a 2015 campaign called Operation ProgramsByMe. Its principal targets are North Korean defectors, human-rights activists, researchers, and journalists, with some cases involving military-related documents. Tradecraft centers on email and mobile-messenger spear-phishing carrying weaponized HWP documents that abuse an EPS scripting vulnerability, alongside malicious LNK, VBScript, and Office documents and a 2018 Flash zero-day. AhnLab has continued tracking the group's evolution, including LNK-delivered RokRAT backdoors that inject decoded payloads into PowerShell processes and exfiltrate victim data through cloud storage services such as pCloud and Yandex.
-
26
Related Actors
-
27
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster