#RedSignature
Incident/Operation
2018-08-21 • Supply Chain Attack Operation Red Signature Targets South Korean Organizations
Operation Red Signature was an information-theft supply-chain attack discovered in mid-2018 against selected organizations in South Korea. Attackers compromised a remote-support provider, stole its code-signing certificate, signed malicious updates, and altered the update server so payloads were delivered only to clients within target organizations’ network ranges. The update channel installed 9002 RAT and additional tools for exploiting an IIS WebDAV flaw and dumping SQL database passwords, indicating interest in web-server and database contents. Selective delivery, abuse of trusted software updates, and a valid stolen certificate helped the campaign evade suspicion and limit exposure.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days