logo

Cisco's Talos Intelligence Group Blog: Korea In The Crosshairs

ID: 2aae9161-6c2e-40db-a5b9-a2d1a4950a59

STIX ID: report--2aae9161-6c2e-40db-a5b9-a2d1a4950a59

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2018-01-16

Last Modified Date: 2018-01-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Talos report analyzes a year of activity by a persistent threat actor (Group 123) that targeted South Korea and other organizations through tailored spearphishing using HWP and Office documents, exploited known CVEs to deliver ROKRAT (including a fileless variant), Freenki, PoohMilk and a disk-wiper module, documents shared code/PDB artifacts across campaigns, catalogs detailed TTPs (process injection, anti-sandbox, cloud-based C2), and provides extensive IoCs (hashes, URLs, domains) for detection and response.