#BigPond

Incident/Operation

2018-11-01 • Since the hacking of Sony Pictures

Operation Big Pond was a 2015–2017 cluster of targeted activity in South Korea presented as suspected Lazarus Group work. Its targets included political institutions, defense contractors, conglomerates, shopping malls, information-technology companies, hosting and asset-management providers, media, logistics services, a financial institution, and cryptocurrency exchanges. The operators exploited browser and font-processing vulnerabilities, including a Windows zero-day used from 2015 before disclosure, and employed oversized or encrypted loaders that unpacked backdoors directly in memory to evade security products. Cryptocurrency-focused attacks also used government-themed and financial document lures to disguise malicious Hangul files.

Tagged Reports

« Back