#KoreanSword
Incident/Operation
2018-11-16 • 금성121(Geumseong121) 정부기반 APT그룹, '코리안 스워드(Operation Korean Sword) 작전' 수행 중
Korean Sword is a 2018 Geumseong121 operation targeting South Korean activists, organizations, and individuals concerned with North Korea for covert information theft. Its malicious HWP documents exploited an EPS vulnerability and evolved from direct startup-folder batch execution to a Visual Basic script that launched a batch file and removed installation artifacts. The chain reconstructed a split executable header to hinder detection, deployed a Themida-packed payload, and installed the remote-access functionality characteristic of the group, while repeated document metadata and code patterns linked the observed variants.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days