Red Eyes

2018-03-05 • Ahnlabhttps://twitter.com/mstoned7/status/966126706107953152

RedEyes is a name AhnLab's security response center uses for a North Korean-linked hacking group it began documenting in March 2018, based on a sixteen-month study of malicious Hangul Word Processor documents collected between September 2016 and December 2017, in which the group, internally labeled Group A, was found responsible for roughly a quarter of the malicious samples. AhnLab treats RedEyes as the same group publicly reported elsewhere as Geumseong121, Group123, ScarCruft, APT37, Reaper, and Ricochet Chollima, tracing its activity back at least five years and noting possible ties to a 2015 campaign called Operation ProgramsByMe. Its principal targets are North Korean defectors, human-rights activists, researchers, and journalists, with some cases involving military-related documents. Tradecraft centers on email and mobile-messenger spear-phishing carrying weaponized HWP documents that abuse an EPS scripting vulnerability, alongside malicious LNK, VBScript, and Office documents and a 2018 Flash zero-day. AhnLab has continued tracking the group's evolution, including LNK-delivered RokRAT backdoors that inject decoded payloads into PowerShell processes and exfiltrate victim data through cloud storage services such as pCloud and Yandex.

Related Actors

Related Reports in This Cluster

Top Authors

View Red Eyes reports only

View Red Eyes reports only