Group123 is a suspected Korean-language espionage threat actor associated with targeted malware campaigns against South Korean users. The group is known for politically themed lures related to the Korean peninsula and for using document-based initial access, particularly Hangul Word Processor content and other decoys written in Korean. Reporting has linked Group123 with malware such as ROKRAT and, with medium confidence, NavRAT. Observed tradecraft includes spearphishing with politically themed documents, exploitation of client-side vulnerabilities, staged shellcode delivery, and abuse of legitimate online services for command and control. In the NavRAT-linked activity, the actor used an HWP document with an embedded EPS object to trigger shellcode, downloaded additional payload material from a compromised Korean website, executed components in memory, established persistence, collected host information, performed process injection into Internet Explorer, and used a legitimate email platform for command exchange and file transfer. NavRAT also supports keylogging, file upload and download, and remote command execution. Group123 has also been associated in public reporting with campaigns distributing documents referencing politics on the Korean peninsula. A separate Android and Windows malware cluster involving KevDroid and PubNubRAT showed only weak overlap with Group123 tradecraft and was not confidently attributed. Overall, the actor is best characterized as a targeted intrusion set focused on South Korean victims, using socially engineered lures, malware implants, persistence, stealthy command channels, and post-compromise collection capabilities consistent with espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of how threat actors can have distinctive operating patterns.
Group123 is conducting targeted spear-phishing campaigns against South Korean users using malicious Hangul Word Processor (HWP) documents. These documents exploit embedded EPS objects to execute shellcode, which downloads and executes the NavRAT remote access trojan. The campaigns leverage real geopolitical events as lures and use local cloud/email providers (such as Naver) for command and control, making detection more difficult. The TTPs are consistent with previous Group123 operations, including the use of ROKRAT and similar infection frameworks.
Mentioned as a possible but unconfirmed link to the investigated Android and Windows malware; the report explicitly says the evidence is too weak to establish attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.