logo

‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group

ID: faa7efff-6d5d-486a-90fd-7c2f0d619f2a

STIX ID: report--faa7efff-6d5d-486a-90fd-7c2f0d619f2a

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2018-10-15

Last Modified Date: 2018-10-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Advanced Threat Research describes 'Operation Oceansalt', a targeted campaign delivering a reconnaissance implant via Korean-language malicious Office documents; Oceansalt reuses code and strings from the 2010 Seasalt/Comment Crew implant, supports drive/file/process reconnaissance, reverse shells, and remote command execution, and was distributed through compromised South Korean websites with control servers observed across multiple countries. The report presents infection waves focusing on South Korean public infrastructure and higher education, expansion to North American targets (financial, healthcare, telecom, agriculture), detailed technical analysis, multiple hashes and IP IOCs, and hypotheses about source-code sharing or false-flag activity.