#FakeCapsule

Incident/Operation

2019-01-20 • 일요일 수행된 APT 변종 공격, 오퍼레이션 페이크 캡슐(Operation Fake Capsule) 주의

Operation Fake Capsule was a January 2019 South Korea-focused APT campaign assessed as government-backed and technically linked to Operation Cobra Venom. It delivered a screen-saver executable disguised as an HWP research document through icon spoofing, extensive whitespace, and a double extension, while falsified build dates complicated timeline analysis. The dropper displayed a benign Korean document, installed a DLL payload under names imitating a Korean security product, separated command-and-control configuration from the main payload, and created a batch file to erase installation traces. Shared network-form handling code further connected the activity to Cobra Venom.

Tagged Reports

« Back