logo

Dalbit__2023__Ahnlab_Dalbit-m00nlight-Chinese-APT-Campaign_02-13-2023.pdf

ID: c3a0a5af-25bf-4faa-a6d5-555c4f181d17

STIX ID: report--c3a0a5af-25bf-4faa-a6d5-555c4f181d17

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2023-03-01

Last Modified Date: 2023-03-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AhnLab ASEC details the Dalbit (m00nlight) campaign targeting primarily Korean organizations since 2022: actors gain initial access via webshells and vulnerable servers, deploy open-source tools (FRP, LCX, Potato exploit families, scanning and dumping utilities), perform internal reconnaissance and credential theft (LSASS dumps, Exchange email extraction), use compromised hosts as proxies for RDP-based lateral movement, and ultimately extort victims by locking drives with BitLocker; the report includes extensive IOCs (hashes, C2s, FRP configs), observed tactics, and remediation recommendations.