#OnionDog

Incident/Operation

2016-03-08 • Operation OnionDog

OnionDog is the name given to activity first observed in 2013 and initially described as a multi-year cyber-espionage campaign against high-profile South Korean energy and transportation targets. The original characterization involved lure documents, droppers, USB-spreading malware, and the ICEFOG backdoor. A later Trend Micro investigation concluded that the roughly 200 associated samples and their callback infrastructure were part of cybersecurity exercises rather than a genuine targeted attack, with servers apparently recording which drill participants were infected. Attribution to North Korean actors should therefore not be treated as established.

Tagged Reports

« Back