#MysteryBaby
Incident/Operation
2018-11-02 • 한국 대상 최신 APT 공격, 작전명 미스터리 베이비(Operation Mystery Baby) 주의!
Operation Mystery Baby was a late-October 2018 South Korea-focused cyber-espionage campaign attributed to a government-backed group and strongly linked by code and delivery patterns to Operation BabyCoin. Malware disguised with the icon of a Korean security product was built in separate 32-bit and 64-bit versions and could steal system information, keystrokes, account data, and other sensitive material. Related activity combined tailored Korean phishing, webmail credential theft, and malicious HWP documents. Its staged payload chain downloaded encrypted components, decrypted them with RC4-derived logic, and used startup shortcuts to maintain execution.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days