#BlackMine
Incident/Operation
2015-11-03 • 검은 광산 작전 (Black Mine Operation) 분석 보고서
BlackMine was a targeted campaign observed from May 2014 through at least July 2015 against organizations in South Korea, including the energy, transportation, telecommunications, broadcasting, IT, finance, and political sectors. Its core Bmdoor loader concealed encrypted payloads at the end of otherwise legitimate-looking executables in a region beginning with the string “BM,” then launched downloaders, information-stealing bots, or remote-control tools in memory. More than 240 Bmdoor samples were identified, and similarities to malware used in the 2013 DarkSeoul disruptions suggested a possible relationship to the same or a related attack group, without establishing definitive attribution.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days