Researchers tied a broader cyber-espionage operation to North Korea-linked actors after uncovering Android spyware variants known as KevDroid and a Windows backdoor dubbed PubNubRAT on infrastructure including cgalim[.]com. The Android malware stole contacts, SMS, account data, device information, screenshots, audio, video, and call recordings, and in some cases attempted rooting through CVE-2015-3636. Investigations also found trojanized Android apps themed around the PyeongChang Winter Games and Bitcoin Ticker Widget, while Windows infections used Korean-language lure documents exploiting CVE-2017-11882 to download malware capable of file theft, command execution, process termination, and screenshot capture.
The activity aligned with a longer-running campaign tracked as Operation Rocket Man, which targeted South Korean organizations, North Korea-related groups, defense entities, and individuals through spear phishing, watering-hole attacks, social-network phishing, torrent-delivered malware, malicious HWP and DOC files, Android APKs, and fake security software. Analysts linked campaigns from 2013 to 2018 through shared domains, malware code, PDB paths, metadata, and command-and-control patterns, including use of hacked Korean websites, cloud services such as Dropbox, Yandex, pCloud, and later PubNub, as well as exploits including CVE-2018-4878 and CVE-2017-8759; false Chinese-language artifacts were assessed as likely deception.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
In August 2018, ESRC discovered a new spear-phishing campaign in which the attacker impersonated a Korean corporate HR representative. The operation used hacked Korean websites and links disguised as attached files, and the malware impersonated a PC security program while using PubNub for command-and-control.
Talos found a second KevDroid Android RAT variant at the same cgalim.com URL in February 2018. This variant added capabilities such as camera and audio recording, web history theft, file theft, and rooting via CVE-2015-3636.
In January 2018, attackers compromised the Korean website ebsmpi.com and made it mimic the Chinese 360 Total Security download page to distribute malware. The campaign delivered Ant_3.5.exe, Ant_4.5.exe, and desktops.ini, reusing the same encryption and infection flow later seen in August 2018.
ESRC connected the Operation Rocket Man activity to a spear-phishing case in September 2017 through shared account names, OLE code patterns, and metadata. The report also tied endlesspaws.com to a 2017 spear-phishing campaign and noted use of CVE-2017-8759 in attacks associated with this infrastructure.
ESRC linked the recurring C2 domain endlesspaws.com to a 2015 watering-hole campaign targeting South Korea-based North Korea-related websites. The domain later reappeared in additional Geumseong121 operations.
ESRC assessed that the North Korea-linked group Geumseong121 had been conducting sustained intrusion operations against South Korean targets since around 2013. Early activity included malware families that used AOL Instant Messenger as a command-and-control channel.
ESRC published a report naming the long-running campaign 'Operation Rocket Man' and attributing it to Geumseong121. The report tied together activity from 2013 through 2018 using shared infrastructure, malware code, PDB paths, metadata, and command-and-control patterns, and assessed Chinese-language artifacts as likely false flags.
Palo Alto Networks Unit 42 published analysis linking KevDroid and related Android downloader apps to the North Korean Reaper group, also known as APT37. The report described trojanized PyeongChang Winter Games and Bitcoin Ticker Widget apps that downloaded spyware from cgalim.com and exfiltrated data to hakproperty.com.
Cisco Talos published research on previously undocumented Android and Windows malware families it named KevDroid and PubNubRAT. The report described Android spyware hosted at cgalim.com and a Windows infection chain using a Korean-language RTF lure exploiting CVE-2017-11882 to deliver PubNub-based RAT payloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 73 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.alyac.co.kr
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.