Cisco's Talos Intelligence Group Blog: Korea In The Crosshairs
ID: 2aae9161-6c2e-40db-a5b9-a2d1a4950a59
STIX ID: report--2aae9161-6c2e-40db-a5b9-a2d1a4950a59
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2018-01-16
Last Modified Date: 2018-01-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Talos report analyzes a year of activity by a persistent threat actor (Group 123) that targeted South Korea and other organizations through tailored spearphishing using HWP and Office documents, exploited known CVEs to deliver ROKRAT (including a fileless variant), Freenki, PoohMilk and a disk-wiper module, documents shared code/PDB artifacts across campaigns, catalogs detailed TTPs (process injection, anti-sandbox, cloud-based C2), and provides extensive IoCs (hashes, URLs, domains) for detection and response.
