Threat Actors Poses as Korean TV Programs’ Writer to Trick Victims and Install Malware
ID: ceb4a7c7-a42b-56bd-946e-2f46ef9b375f
STIX ID: report--ceb4a7c7-a42b-56bd-946e-2f46ef9b375f
Feed Name: cybersecurityNews.com
Operation Artemis uses socially engineered emails impersonating Korean broadcasting writers to deliver malicious Hangul (HWP) documents that execute OLE objects and drop executables and version.dll libraries. The campaign employs DLL side-loading (targeting legitimate Sysinternals utilities), multi-layer XOR decryption (including SSE-accelerated routines), steganography, and ultimately deploys the RoKRAT data-stealing payload, maintaining C2 infrastructure on Yandex Cloud with activity between October 2023 and February 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
