#BitterBiscuit
Incident/Operation
2017-10-12 • 오퍼레이션 비터 비스킷 분석 보고서
BitterBiscuit is a long-running targeted campaign observed from at least 2011 through 2017 against government, military, defense-industry, and information-technology organizations, principally in South Korea with earlier activity affecting Japan and India. The operators used Bisonal and Dexbia malware, spear-phishing archives, malicious Word add-ins, and persistence through a user Run key. Investigated infections deployed multiple backdoors, used HTTP command-and-control, and downloaded and executed additional payloads, while code and encoding similarities linked later tooling to the Bisonal family.
-
3
Tagged Reports
-
2
Unique Authors
-
1,194
Active Days