Group 123 is a threat actor associated with intelligence-gathering and destructive operations, primarily targeting South Korean users. Its activity spans at least August 2016 through January 2018 and includes the Golden Time, Evil New Year, Are You Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018 campaigns. FreeMilk targeted several financial institutions outside Korea. The actor uses fluent Korean-language spear-phishing lures addressing Korean reunification, North Korean political developments, and human rights. Its country of origin and state sponsorship are not established. Group 123 primarily delivers ROKRAT through malicious Hancom Hangul documents, using embedded Encapsulated PostScript exploits, malicious OLE objects, and staged shellcode. Its campaigns have exploited CVE-2013-0808 and, in FreeMilk, CVE-2017-0199 through Microsoft Office documents. Supporting tools include Freenki and PoohMilk, which provide reconnaissance, payload delivery, and persistence. The actor has compromised legitimate Korean infrastructure and abused legitimate cloud services, including Twitter, Yandex, MediaFire, pCloud, Dropbox, and Box, for command-and-control and document exfiltration. Observed techniques include system and process reconnaissance, browser credential theft, process injection, obfuscation, anti-analysis checks, and memory-only payload execution. Group 123 also deployed a destructive ROKRAT module capable of overwriting the master boot record and rebooting the affected system. Its campaigns demonstrate both information collection and destructive capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The email's attachments are two different HWP documents, both leveraging same vulnerability (CVE-2013-0808). This vulnerability targets the EPS (Encapsulated PostScript) format. The purpose of the shellcode is to download a payload from the Internet.
The attackers exploited CVE-2017-0199 in order to download and execute a malicious HTA document inside of Microsoft Office.
"...one of the samples, the SLUB loader exploiting CVE-2019-0803, contained a version resource section that included intentionally misleading planted data."
60 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in a referenced report URL. The supplied content does not explicitly describe the group's operations or attribute exploitation of CVE-2018-4878 to it.
Mentioned only as an example of how threat actors can have distinctive operating patterns.
Group123 is conducting targeted spear-phishing campaigns against South Korean users using malicious Hangul Word Processor (HWP) documents. These documents exploit embedded EPS objects to execute shellcode, which downloads and executes the NavRAT remote access trojan. The campaigns leverage real geopolitical events as lures and use local cloud/email providers (such as Naver) for command and control, making detection more difficult. The TTPs are consistent with previous Group123 operations, including the use of ROKRAT and similar infection frameworks.
Mentioned as a possible but unconfirmed link to the investigated Android and Windows malware; the report explicitly says the evidence is too weak to establish attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.