#BookCodes

Incident/Operation

2020-04-01 • TTPs#1 홈페이지를 통한 내부망 장악 사례 분석

Operation BookCodes is a Lazarus Group campaign targeting South Korean organizations since 2019, including maritime, media, security-software, and other selected companies and individuals. Initial access included spearphishing documents, compromised web and hosting servers, and a supply-chain path abusing trusted software distribution; command traffic contained the distinctive Bookcodes signature. Operators built farms of compromised domestic infrastructure, deployed remote-control malware, collected information, and propagated through victim environments, while related tooling and architecture connected the activity to other Lazarus operations.

Tagged Reports

« Back