#EvilPlane

Incident/Operation

2022-12-07 • 오퍼레이션 이블플레인(Operation EvilPlane) : 국내 이용자의 개인정보가 담긴 파일을 이용한 APT 공격

Operation EvilPlane was a December 2022 targeted attack against users in South Korea that used a malicious Word document containing personal information as a lure. Attributed by the analysis to the North Korean-linked Konni group, the document used remote template injection to retrieve a macro-enabled template, then downloaded additional components, bypassed User Account Control, and installed a service. The final payload uploaded host information and accepted remote commands, while the lure's hidden text and privilege-escalation module matched techniques previously associated with Konni activity.

Tagged Reports

« Back