‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group
ID: faa7efff-6d5d-486a-90fd-7c2f0d619f2a
STIX ID: report--faa7efff-6d5d-486a-90fd-7c2f0d619f2a
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2018-10-15
Last Modified Date: 2018-10-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Advanced Threat Research describes 'Operation Oceansalt', a targeted campaign delivering a reconnaissance implant via Korean-language malicious Office documents; Oceansalt reuses code and strings from the 2010 Seasalt/Comment Crew implant, supports drive/file/process reconnaissance, reverse shells, and remote command execution, and was distributed through compromised South Korean websites with control servers observed across multiple countries. The report presents infection waves focusing on South Korean public infrastructure and higher education, expansion to North American targets (financial, healthcare, telecom, agriculture), detailed technical analysis, multiple hashes and IP IOCs, and hypotheses about source-code sharing or false-flag activity.
