오퍼레이션 블랙버드(Operation Blackbird)', 금성121의 모바일 침공

2018-12-13 • ESTSecurity • ‘Operation Blackbird', Venus 121's mobile invasion •

http://blog.alyac.co.kr/2035

Thumbnail for 오퍼레이션 블랙버드(Operation Blackbird)', 금성121의 모바일 침공

ESRC attributes Operation Blackbird activity to the suspected Geumseong 121 group and shows the operation expanding from earlier server and PC targeting into Android mobile espionage. The campaign targeted North Korean defectors and related individuals by sending direct app-install links through SNS comments or messengers such as KakaoTalk, indicating a narrowed, targeted delivery model rather than mass malware distribution. The spyware history includes droppers that abused Samsung and LG device vulnerabilities, including CVE-2015-7888, and later apps disguised as useful software to persuade victims to install them. The apps registered device details, downloaded command files and additional DEX modules, collected sensitive data including account and document information, and exfiltrated encrypted results to Dropbox, Yandex, or compromised web servers. Dropbox folders tied to the operation reportedly exposed attacker test data, suspected operator email and KakaoTalk profile information, exploit code, and victim personal data, giving defenders infrastructure and behavioral evidence to track the activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bded85d7024b6cf86cc9ce45ec851c8… 2018-12-13 2023-10-04
HASH 6a436aca00171111e8bb3e66f0ebe48… 2018-12-13 2018-12-13

Related Actors

Related Reports

« Back