logo

Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide

ID: 365fb556-e25f-49ad-8920-570f4e1748d1

STIX ID: report--365fb556-e25f-49ad-8920-570f4e1748d1

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2018-04-25

Last Modified Date: 2018-04-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Advanced Threat Research uncovered "Operation GhostSecret," a global data-reconnaissance campaign attributed with high confidence to Hidden Cobra (North Korean APT). The actors used multiple implants — including a Destover-like backdoor, a Bankshot-like variant, and an undocumented SSL listener Proxysvc — leveraging FakeTLS/PolarSSL and control servers (e.g., 203.131.222.83 hosted at Thammasat University) to collect and exfiltrate data from critical infrastructure, finance, healthcare, telecom, and other sectors; the report includes technical analysis, PE rich-header correlations, command/telemetry behavior, IPs and file hashes as indicators of compromise.