#HEARTBEAT
Incident/Operation
HeartBeat was a targeted espionage campaign active from at least 2009 against South Korean government bodies and related organizations, including political parties, media, a national policy institute, a military branch, and a small-business organization. Operators likely used spearphishing to deliver bundled files that displayed convincing JPG, PDF, spreadsheet, or Hangul decoys while silently installing a remote-access tool. The malware injected a DLL into a legitimate process, persisted as a service, and enabled process control, file transfer, command-shell access, drive and file discovery, reboot, update, and removal. Its infrastructure used redirection services and likely compromised hosts as proxies; the responsible actors remained unidentified.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days