TA-Red Ant

2024-10-15 • AhnlabASEC과 국가사이버안보센터(NCSC), 합동 보고서 배포 및 Microsoft 브라우저…

TA-RedAnt is the name used by AhnLab and South Korea’s National Cyber Security Center for the North Korean threat actor also known as RedEyes, ScarCruft, Group123, and APT37. Their October 2024 joint reporting attributed Operation Code on Toast to the group. TA-RedAnt has targeted North Korean defectors and specialists on North Korean affairs through spear-phishing email, malicious Android packages, and Internet Explorer vulnerabilities. In Code on Toast, the actor compromised a Korean online-advertising server and injected exploit code into advertisements rendered by desktop toast-notification software that still relied on Internet Explorer’s obsolete WebView engine. Exploitation of CVE-2024-38178 occurred without user interaction, downloaded malware to affected Windows systems, and enabled remote commands. The operation demonstrates the group’s willingness to compromise upstream content infrastructure and exploit unsupported browser components embedded inside otherwise legitimate applications to reach carefully selected victims.

Related Actors

Related Reports in This Cluster

Top Authors

View TA-Red Ant reports only

View TA-Red Ant reports only