Lazarus_Group__2018__wp-dissecting-operation-troy.pdf
ID: 4482305f-77b9-4b9a-8052-6d571c9a1e95
STIX ID: report--4482305f-77b9-4b9a-8052-6d571c9a1e95
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2013-07-04
Last Modified Date: 2013-07-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Labs' report 'Dissecting Operation Troy' analyzes a long-running (2009–2013) nation-scale espionage and destructive campaign targeting South Korea that culminated in the March 20, 2013 'Dark Seoul' incident. The authors detail multiple components (remote-access Trojans, droppers, MBR wipers such as KillMBR samples), an encrypted IRC/HTTP command-and-control infrastructure, data-exfiltration and drive-scanning tooling, compile-path and code-reuse evidence linking variants to a single actor (NewRomanic Cyber Army Team), and provide IOCs including MD5s, compile dates, domains, strings and a shared zip password used for stolen archives.
