#HEARTBEAT

Incident/Operation

2013-01-03 • The HeartBeat APT Campaign

HeartBeat was a targeted espionage campaign active from at least 2009 against South Korean government bodies and related organizations, including political parties, media, a national policy institute, a military branch, and a small-business organization. Operators likely used spearphishing to deliver bundled files that displayed convincing JPG, PDF, spreadsheet, or Hangul decoys while silently installing a remote-access tool. The malware injected a DLL into a legitimate process, persisted as a service, and enabled process control, file transfer, command-shell access, drive and file discovery, reboot, update, and removal. Its infrastructure used redirection services and likely compromised hosts as proxies; the responsible actors remained unidentified.

Tagged Reports

« Back