Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Shadow Force

Operation Shadow Force

TLP:CLEAR
Active

Also known as: TA-ShadowCricket, Larva-24013

Description

Operation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity that attacks Korean companies and organizations. The group's first confirmed attack was in March 2013, but considering the date of malware creation, it is likely to have been active before 2012. Since the malware used mainly by them is Shadow Force, it was named Operation Shadow Force, and it has not been confirmed whether the attacker is associated with a known group.

AI Analysis

· 1 week ago

Executive Summary

Operation Shadow Force is a cyber threat actor targeting primarily South Korean companies and organizations since at least 2013. The group is associated with the Shadow Force malware family and has demonstrated persistence in attacking critical sectors such as manufacturing and finance. While their exact motivations are unclear, they appear to focus on strategic or financial gains through targeted attacks.

Goals & Targeting

Operation Shadow Force's strategic objectives remain somewhat ambiguous but are likely centered on either financial gain or gathering sensitive information from targeted sectors. Their primary victims tend to be large corporations in manufacturing, finance, and technology industries within South Korea. This suggests the group is highly focused geographically and sectorally, possibly indicating a nation-state actor or a financially motivated group exploiting regional vulnerabilities for maximum impact.

Enhanced Description

Operation Shadow Force is a persistent cyber threat actor known for targeting South Korean businesses and organizations since 2013. The group gained its name from the Shadow Force malware family it extensively uses, which has been active between 2013 and 2020. The group's activities suggest a strategic focus on sectors that hold significant economic or political value in South Korea, indicating possible state-sponsored or financially motivated objectives. Despite their extensive operational history, Operation Shadow Force remains elusive; no confirmed links to known threat groups have been established. Their modus operandi typically involves sophisticated攻击手段,包括定制恶意软件、持久化技术以及数据外传机制。The longevity of their campaigns underscores a capability for long-term strategic operations.

Key Capabilities

  • Spear-phishing campaigns using malicious email attachments
  • Deployment of custom malware for persistence and data exfiltration
  • Use of backdoors and remote access tools to maintain control over infected systems
  • Sophisticated data collection and exfiltration techniques
  • Long-term operational persistence across targeted organizations

MITRE ATT&CK Tactics

Espionage
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.003 - Spear Phishing Attachment: Macro Malware
T1003 - Keylogging
T1566.001 - Exfiltration Over Network - Encrypted Channels

Software / Tooling

Shadow Force malware
Custom-backdoor implants
Remote access tools (RAT)

Campaigns & Victims

Operation Shadow Force has demonstrated a consistent focus on South Korean targets, suggesting a geographically constrained campaign strategy. Their campaigns often involve prolonged periods of lateral movement and data collection within compromised networks, indicative of an intent to maximize the value of stolen information. Notable past operations include attacks that have affected high-profile companies in manufacturing and finance sectors.

IOC Patterns

  • Spear-phishing emails with malicious Office document attachments
  • Presence of Shadow Force malware components in network traffic
  • Use of custom scripts or DLLs dropped during infection
  • Encrypted communication channels for command and control
  • Specific timestamps related to Shadow Force malware activity

Recommended Actions

  • Implement rigorous email filtering and detection mechanisms for malicious attachments
  • Monitor network traffic for signs of data exfiltration, particularly encrypted transfers
  • Deploy endpoint detection and response (EDR) solutions to detect custom malware signatures
  • Conduct regular security audits on critical sector organizations
  • Educate employees regarding phishing and social engineering tactics

Suggested Tags

APT
Nation-state
Esperón
Financial sector
Manufacturing
South Korea

Confidence Assessment

High confidence in the identification of Operation Shadow Force as a persistent threat actor targeting South Korean entities, with significant intelligence supporting their use of Shadow Force malware. However, gaps exist regarding their exact motivations and operational TTPs beyond the basics described.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
APT
Nation-state
Esperón
Financial sector
Manufacturing
South Korea

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.