#BabyCoin

Incident/Operation

2018-04-19 • 2010년 해외 대상 APT 공격자, 오퍼레이션 베이비 코인(Operation Baby Coin)으로 한국 귀환

Operation BabyCoin was a 2018 spear-phishing campaign against a selected South Korean target, linked through code and operational traces to a state-supported group active from roughly 2010 to 2014 against senior overseas diplomatic and security personnel. The campaign used a Korean-language malicious document themed around cryptocurrency while planting Chinese-looking metadata as a possible false flag. Exploitation of a Microsoft Office equation-editor vulnerability triggered a multi-stage download chain that collected browser and email-account data, selected payloads for the victim’s processor architecture, and established persistence through startup shortcuts.

Tagged Reports

« Back