#RoundTable
Incident/Operation
2019-02-21 • 2차 북미정상회담 좌담회 초청으로 수행된 최신 APT 공격, '작전명 라운드 테이블(Operation Round Table)'
Operation RoundTable was a February 2019 state-sponsored spear-phishing campaign that used an invitation to a special discussion of the second United States–North Korea summit as its lure. A malicious HWP attachment embedded PostScript and shellcode that exploited the document processor, contacted compromised infrastructure, retrieved encrypted data disguised as an image, and created a DLL for further command execution. Strong similarities to Operation BlackLimousine and shellcode patterns seen in the 2014 Korea Hydro & Nuclear Power intrusion linked the activity to the same established threat lineage, though the responsible organization was not named definitively.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days