TEMP.Reaper
2018-02-03 • Mandiant • Attacks Leveraging Adobe Zero-Day (CVE-2018-4878)
TEMP.Reaper is the name FireEye, now part of Mandiant, assigned to a suspected North Korean threat group it began publicly tracking in February 2018, after identifying it as the actor behind exploitation of an Adobe Flash zero-day distributed via malicious Office documents to South Korean targets that ultimately delivered the DOGCALL backdoor. FireEye observed TEMP.Reaper operators interacting directly with command-and-control infrastructure from IP addresses on North Korea's STAR-KP network in Pyongyang, and documented the group's use of a wiper malware family called RUHAPPY, distinct from its otherwise espionage-focused operations. Historically the group's targeting concentrated on the South Korean government, military, and defense-industrial base, with lure themes tied to Korean reunification and North Korean defectors, before expanding internationally in 2017 to targets in Japan, Vietnam, and the Middle East across a wider range of industry verticals including chemicals, electronics, manufacturing, aerospace, automotive, and healthcare. FireEye assessed with high confidence that the group operates on behalf of the North Korean government and aligned TEMP.Reaper with activity separately reported by other researchers as ScarCruft and Group123.
-
26
Related Actors
-
8
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster