#Onezero
Incident/Operation
2018-05-28 • 판문점 선언 관련 내용의 문서로 수행된 '작전명 원제로(Operation Onezero)' APT 공격 분석
Onezero was a May 2018 HWP-based operation using Panmunjom Declaration-themed documents and tradecraft linked to Kimsuky. Its exploit shellcode matched code used in a 2014 attack on a South Korean power institution, while later stages executed a DLL through a legitimate Windows registration utility, gathered system information, and used trusted cloud storage and compromised South Korean web infrastructure for command-and-control and payload delivery. Overlapping filenames, developer artifacts, and infrastructure also suggested operational connections between Kimsuky and Geumseong121 activity, without proving that the labels are identical.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days