#Poseidon
Incident/Operation
2026-01-18 • 포세이돈 작전: 구글 광고 리다이렉션 메커니즘을 악용한 스피어 피싱 공격
Poseidon is a Konni APT operation observed in 2025 and early 2026 against selected South Korean recipients. Spear-phishing messages impersonated North Korean human-rights organizations and financial institutions, disguised malicious links as advertising URLs, and abused legitimate ad-click redirection to bypass filtering and user suspicion. Victims were routed through compromised WordPress sites used for payload delivery and command-and-control. A PDF-masquerading AutoIt script loaded EndRAT, while replaceable compromised infrastructure and trusted redirection services reduced the effectiveness of static signatures and domain-based blocking.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days