#DOKKAEBI

Incident/Operation

2018-08-01 • Campaign DOKKAEBI: Documents of Korean and Evil Binary

Campaign DOKKAEBI is an analytical grouping of connected intrusions that used malicious Korean HWP documents between 2015 and the first half of 2018. The activity was divided among Bluenoroff, Kimsuky, and ScarCruft based on differences in document characteristics and follow-on malware. Similarities in the groups’ operational backgrounds, objectives, and attack methods led researchers to treat the cases as a continuous series of related compromises rather than a single actor’s discrete operation.

Tagged Reports

« Back