#MysteryDot
Incident/Operation
2018-11-01 • Since the hacking of Sony Pictures
Operation Mystery Dot covers Lazarus-linked backdoor activity observed from 2011 through 2014 and identified as an early precursor to malware used in the Sony Pictures intrusion. Its droppers and Redobot backdoors shared unusual API-name obfuscation using inserted dots, a recurring XOR decryption key, distinctive command-shell strings, self-deletion behavior, and Lazarus-associated internal markers. The backdoors initialized direct command-and-control communications, accepted remote commands, and used fake SSL-related code to make their traffic appear legitimate, providing a technical lineage across several years of activity.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days