#Oceansalt

Incident/Operation

2018-10-18 • Operation Oceansalt Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group

Operation Oceansalt was a focused 2018 reconnaissance campaign delivered in five waves against Korean-speaking users, primarily in South Korea, with additional victims in the United States and Canada. Its first-stage implant collected system data, executed attacker commands, and was distributed through compromised South Korean websites. The malware reused substantial code from the circa-2010 Seasalt implant associated with the Chinese Comment Crew/APT1 group, but the reuse did not prove that Comment Crew conducted Oceansalt; the responsible actor and ultimate operational objective remained unknown.

Tagged Reports

« Back