#GoldenAxe2
Incident/Operation
2018-05-23 • Operation GoldenAxe2:ActiveX attacks targeting reunification, diplomacy and security stakeholders
GoldenAxe2 is a North Korean-linked watering-hole operation observed in May 2018 against South Korean specialists in reunification, diplomacy, and security. Attackers injected malicious scripts into the website of a policy research institute and exploited a vulnerable ActiveX groupware control to execute malware on visitors’ systems. The payload collected host information, communicated with command-and-control infrastructure, and downloaded additional malware; it was described as the latest variant of a longer GoldenAxe activity cluster that had abused ActiveX weaknesses in Korean software since 2007.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days