#GhostPuppet
Incident/Operation
2018-09-24 • 최신 APT 캠페인, 작전명 유령 꼭두각시(Operation Ghost Puppet)
Operation GhostPuppet was a targeted campaign identified in August 2018 that used a malicious Hangul Word Processor document styled as a notice about an alleged financial-law violation. The document embedded compressed PostScript that exploited the GhostScript engine, decoded shellcode, injected a thread into the Windows shell, and downloaded a remote-access payload. Its use of the Korean HWP format suggests a focus on users of software common in South Korean government environments, while the final malware provided command-and-control and remote system control.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days