Dark Seoul is a threat actor name associated with destructive and disruptive intrusions linked to North Korean activity. The name is most widely associated with the 2013 attacks against South Korean banks and broadcasters, which involved data destruction, and it has also been referenced in connection with later North Korea-linked operations showing similar tradecraft. Reporting further associates Dark Seoul with the 2022 compromise of an Argentinian government agency in which operators exploited CVE-2021-44228 in VMware Horizon, used privileged or compromised accounts, created masqueraded Windows services and scheduled tasks, disabled security controls, dumped credentials including NTDS data, scanned the network, moved laterally with SMBExec, transferred tools with PowerShell, and deployed HolyGhost ransomware alongside XMRIG cryptomining. Dark Seoul-linked activity therefore spans destructive operations, ransomware deployment, credential access, lateral movement, persistence, defense evasion, reconnaissance, and post-compromise network-wide propagation. The actor is commonly discussed in the broader context of North Korean cyber operations and overlaps in reporting with other DPRK-linked malware and campaigns, including HolyGhost.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive cyber operations involving data-wiping attacks against South Korean banks and broadcasters; discussed as a possible source of tooling or operational similarity to the Sony Pictures attack.
Destructive cyber operations involving data-wiping attacks against South Korean banks and broadcasters; discussed as a possible linked or similar actor in relation to the Sony attack.
Attack against an Argentinian government agency involving exploitation of Log4Shell in VMware Horizon, credential dumping, lateral movement, miner deployment, and ransomware execution via HolyGhost.
Described using scheduled tasks for persistence/execution and masquerading services as legitimate ones.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.