News broke today that newly discovered first-stage implant targeting Korean-speaking victims borrows code from another reconnaissance tool linked to Comment Crew, a Chinese nation-state threat actor that was exposed in 2013 following cyber espionage campaigns against the United States. Dubbed Oceansalt, the threat has been spotted on machines in South Korea, the United States, and Canada. The adversary used spear phishing to lure victims into opening Microsoft Excel and Word documents with content in Korean, specially crafted to download the malware.
Ross Rustici, Senior Director for Intelligence Services at Cybereason:
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.