Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide
ID: 365fb556-e25f-49ad-8920-570f4e1748d1
STIX ID: report--365fb556-e25f-49ad-8920-570f4e1748d1
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2018-04-25
Last Modified Date: 2018-04-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Advanced Threat Research uncovered "Operation GhostSecret," a global data-reconnaissance campaign attributed with high confidence to Hidden Cobra (North Korean APT). The actors used multiple implants — including a Destover-like backdoor, a Bankshot-like variant, and an undocumented SSL listener Proxysvc — leveraging FakeTLS/PolarSSL and control servers (e.g., 203.131.222.83 hosted at Thammasat University) to collect and exfiltrate data from critical infrastructure, finance, healthcare, telecom, and other sectors; the report includes technical analysis, PE rich-header correlations, command/telemetry behavior, IPs and file hashes as indicators of compromise.
