logo

Threat Actors Poses as Korean TV Programs’ Writer to Trick Victims and Install Malware

ID: ceb4a7c7-a42b-56bd-946e-2f46ef9b375f

STIX ID: report--ceb4a7c7-a42b-56bd-946e-2f46ef9b375f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Operation Artemis uses socially engineered emails impersonating Korean broadcasting writers to deliver malicious Hangul (HWP) documents that execute OLE objects and drop executables and version.dll libraries. The campaign employs DLL side-loading (targeting legitimate Sysinternals utilities), multi-layer XOR decryption (including SSE-accelerated routines), steganography, and ultimately deploys the RoKRAT data-stealing payload, maintaining C2 infrastructure on Yandex Cloud with activity between October 2023 and February 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.