Researchers linked multiple targeted intrusions in Russia, South Korea, and Japan to the Bisonal backdoor family, also referred to in some analysis as Korlia and associated with the Operation Bitter Biscuit cluster. Unit 42 reported a previously undocumented Bisonal variant used against a defense-related company in Russia and an organization in South Korea, delivered through spear-phishing emails carrying document-themed decoys such as spoofed Rostec material and Korean Coast Guard employment files. The malware used hard-coded dynamic DNS infrastructure, HTTP POST communications over port 443, campaign tracking codes including 0425god and pmo, and backdoor functions for reconnaissance, process control, shell access, file download, execution, and file creation.

Pull IOCs and campaign context straight into your stack.
13 events from the most recent confirmed update back to the earliest known activity.
Unit 42 publicly reported the Russia and South Korea campaign, detailing the previously undocumented Bisonal variant, its RC4-encrypted C2 traffic, decoy documents, and links to a likely single long-running threat group.
Rostec published an article about housing plans for defense industry workers that attackers later copied into a decoy PDF used in the Russia-targeted phishing attack.
A public reverse-engineering writeup documented the Korlia backdoor, noted its "bisonal" marker, described its XOR-based decoder and RAT capabilities, and published related sample configuration data and YARA guidance.
Unit 42 assessed that the newer Bisonal variant later seen in attacks against Russia and South Korea had been active since at least 2014.
After confirming the vulnerability, the attackers used tools.exe to exploit MS17-010 and upload Acrobat.exe to c:\windows\tasks\conhost.exe on the Active Directory server.
At 14:26, the attackers used checkers.exe against an Active Directory server at 192.168.66.50 and determined the Windows Server 2012 R2 host was unpatched for MS17-010.
At 13:56, the attackers downloaded and ran conhost.exe to steal operating system account passwords, but the attempt failed and the tool was deleted.
At 13:51, the attackers used getwebpass.exe to try to steal credentials from Internet Explorer, Firefox, Thunderbird, Chrome, and Yandex, but no saved passwords were recovered from the infected host.
At 12:32, the attackers mapped a network drive with net use, compressed stolen files into 2 MB WinRAR archives, and uploaded them to command-and-control infrastructure.
The intrusion timeline shows attacker interaction beginning at 11:55, shortly after csrcc.exe executed on the compromised system.
The attacker dropper executed csrcc.exe on the victim host, establishing persistence via the current user's Run registry key and beginning HTTP-based command-and-control activity.
A spearphishing email carrying an ACE archive and two Word documents exploited CVE-2018-20250 to place a malicious Word add-in named word.wll in Word’s add-in folder, initiating a targeted intrusion attributed to the Operation Bitter Biscuit cluster.
In early May, attackers targeted at least one defense-related company in Russia and one unidentified organization in South Korea with a previously undocumented Bisonal variant delivered via document-themed lures.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 54 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcegithub.com
Open sourcejsac.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.