logo

HAZY_TIGER__2019__ASEC_REPORT_vol.93_ENG.pdf

ID: a97e1f97-4137-4bb4-b8a2-d62db1e87c52

STIX ID: report--a97e1f97-4137-4bb4-b8a2-d62db1e87c52

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2019-01-16

Last Modified Date: 2019-01-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASEC Q4 2018 analyzes two active threats: Seon Locker ransomware (and GandCrab deliveries) propagated via a dual drive-by download using the GreenFlash Sundown exploit kit that leverages CVE-2018-4878 and fileless PowerShell execution, and the long-running Operation Bitter Biscuit campaign (Bisonal/Bisoaks) targeting Korean government, defense and marine sectors; the report provides technical breakdowns, sample code, IoCs (file hashes, C2 URLs, filenames) and behavioral indicators for detection and response.