Executive Summary
Brave Prince is a Korean-language Windows implant closely related to Gold Dragon, first seen in December 2017. It was active during 2018 Olympic security breaches alongside RunningRAT, targeting infrastructure of the Pyeongchang Winter Games. The malware facilitates persistence and covert exfiltration of sensitive information.
Enhanced Description
Brave Prince is a Korean-language Windows implant that first appeared in the wild in December 2017. The code base and operational characteristics closely resemble those of Gold Dragon, another well‑documented remote access trojan (RAT) used by advanced threat actors during the 2018 Pyeongchang Winter Olympics. Analysts have linked Brave Prince to the same malicious campaigns that included Gold Dragon and RunningRAT, indicating a coordinated effort to target Korean entities involved in Olympic planning and logistics. While publicly available documentation is limited, existing reports reference its presence from McAfee’s analysis of the broader Gold Dragon family. The implant appears designed for persistence, lateral movement among Windows hosts, and stealthy exfiltration of sensitive data. Given its association with politically motivated operations, the malware likely supports long‑term espionage objectives rather than opportunistic ransomware or destructive payloads.
Key Capabilities
Confidence Assessment
Data about Brave Prince is derived from limited secondary sources; technical details such as file names, payloads, or network indicators are not disclosed publicly, creating uncertainty in detection signatures. Further analysis of malware samples and network traffic would strengthen confidence. suggested_tags
Brave Prince is a Korean-language implant that was first observed in the wild in December 2017. It contains similar code and behavior to Gold Dragon, and was seen along with Gold Dragon and RunningRAT in operations surrounding the 2018 Pyeongchang Winter Olympics. (Citation: McAfee Gold Dragon)