#Starcruiser
Incident/Operation
Operation Starcruiser was an April 2018 cyber-espionage campaign that persistently targeted prominent people in South Korea’s cryptocurrency sector. Its downloader components masqueraded as video files and installed DLL payloads that exfiltrated host information to newly established command infrastructure. Near-identical functions, command-and-control packet logic, form-data fields, development patterns, and related server paths connected Starcruiser to the preceding Operation Battlecruiser. The activity was attributed to a state-backed group conducting continuing espionage operations, with language settings and infrastructure details changing between the two campaigns while the underlying malware workflow remained substantially the same.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days