#BitterBiscuit

Incident/Operation

2017-10-12 • 오퍼레이션 비터 비스킷 분석 보고서

BitterBiscuit is a long-running targeted campaign observed from at least 2011 through 2017 against government, military, defense-industry, and information-technology organizations, principally in South Korea with earlier activity affecting Japan and India. The operators used Bisonal and Dexbia malware, spear-phishing archives, malicious Word add-ins, and persistence through a user Run key. Investigated infections deployed multiple backdoors, used HTTP command-and-control, and downloaded and executed additional payloads, while code and encoding similarities linked later tooling to the Bisonal family.

Tagged Reports

« Back