#FreeMilk

Incident/Operation

2017-10-05 • FreeMilk: A Highly Targeted Spear Phishing Campaign

FreeMilk was a limited, highly targeted spearphishing campaign identified in May 2017 against a Middle Eastern bank, European intellectual-property firms, an international sporting organization, and individuals linked to a Northeast Asian country. Attackers hijacked legitimate email conversations and sent recipient-specific Microsoft Word decoys exploiting a remote-code-execution vulnerability, which installed the PoohMilk and Freenki payloads. Later code analysis connected FreeMilk’s ROKRAT-related components to Final1stspy and the wider APT37 toolset, supporting a relationship to North Korean activity while distinguishing the campaign name from its individual malware payloads.

Tagged Reports

« Back