#BattleCruiser

Incident/Operation

2018-04-11 • 오퍼레이션 배틀크루저' 다양한 취약점으로 국내외 APT 공격 지속

Operation BattleCruiser is a Lazarus Group campaign observed in 2018 against selected South Korean and overseas targets, including defense, security, public-sector, academic, financial, and cryptocurrency-related organizations. It used spearphishing documents exploiting HWP or Microsoft Office vulnerabilities to retrieve platform-specific DLL payloads disguised with media or archive-like extensions. Recurrent internal filenames, shared communications code, Korean-language resources, and Manuscrypt-family payloads linked multiple waves, including renewed activity in October 2018 that delivered encoded backdoors from compromised websites.

Tagged Reports

« Back