#DarkHorse
Incident/Operation
2023-10-16 • Operation DarkHorse CHM 기반 공격 분석
Operation DarkHorse is a phishing campaign tracked from early 2022 through at least the second half of 2023, initially using cryptocurrency and game-server development themes before shifting toward financial contracts, card-limit changes, insurance payments, and impersonation of financial companies. The operators delivered malicious compiled HTML Help files by targeted email; embedded scripts first wrote and ran VBS files and later used compiled JSE payloads. Attribution remains assessed rather than definitive: some analysts suspected APT37, but similarities cited in the campaign analysis instead point to Kimsuky.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days