#GhostRifle
Incident/Operation
Operation Ghost Rifle was a South Korea-focused intrusion cluster that emerged in 2015 and primarily targeted the defense industry. Operators impersonated the organizer of the Seoul International Aerospace and Defense Exhibition in emails to participating companies, delivering exploit-bearing attachments or malicious Office macros with exhibition-related content. AhnLab associated the cluster with Rifdoor and GhostRat and linked it to attacks on a cybersecurity company in early 2016 and a major company’s network in June 2016. In the latter incident, attackers exploited an asset-management platform’s file-distribution function to deploy malware, and more than 40,000 documents were reportedly leaked. Its relationship to Red Dot and other contemporary intrusion clusters remains unresolved.
-
2
Tagged Reports
-
1
Unique Authors
-
10
Active Days