#DragonMessenger

Incident/Operation

2019-11-11 • 금성121, 북한 이탈주민 후원 사칭 '드래곤 메신저' 모바일 APT 공격 수행

DragonMessenger was a 2019 mobile APT operation attributed to the North Korean-linked Geumseong121 threat group. It focused on North Korean defectors, North Korea-related organizations, and other people working on North Korea issues by promoting Android applications through email, social media, website comments, a deceptive donation site, and the official Google Play store. The apps posed as support or private-messaging services, gathered prospective targets into an attacker-controlled community, stored account credentials in plaintext local configuration, and shared links with earlier malicious mobile activity.

Tagged Reports

« Back