Also known as: TA-ShadowCricket, Larva-24013
Operation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity that attacks Korean companies and organizations. The group's first confirmed attack was in March 2013, but considering the date of malware creation, it is likely to have been active before 2012. Since the malware used mainly by them is Shadow Force, it was named Operation Shadow Force, and it has not been confirmed whether the attacker is associated with a known group.
Executive Summary
Operation Shadow Force is a cyber threat actor targeting primarily South Korean companies and organizations since at least 2013. The group is associated with the Shadow Force malware family and has demonstrated persistence in attacking critical sectors such as manufacturing and finance. While their exact motivations are unclear, they appear to focus on strategic or financial gains through targeted attacks.
Goals & Targeting
Operation Shadow Force's strategic objectives remain somewhat ambiguous but are likely centered on either financial gain or gathering sensitive information from targeted sectors. Their primary victims tend to be large corporations in manufacturing, finance, and technology industries within South Korea. This suggests the group is highly focused geographically and sectorally, possibly indicating a nation-state actor or a financially motivated group exploiting regional vulnerabilities for maximum impact.
Enhanced Description
Operation Shadow Force is a persistent cyber threat actor known for targeting South Korean businesses and organizations since 2013. The group gained its name from the Shadow Force malware family it extensively uses, which has been active between 2013 and 2020. The group's activities suggest a strategic focus on sectors that hold significant economic or political value in South Korea, indicating possible state-sponsored or financially motivated objectives. Despite their extensive operational history, Operation Shadow Force remains elusive; no confirmed links to known threat groups have been established. Their modus operandi typically involves sophisticated攻击手段,包括定制恶意软件、持久化技术以及数据外传机制。The longevity of their campaigns underscores a capability for long-term strategic operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operation Shadow Force has demonstrated a consistent focus on South Korean targets, suggesting a geographically constrained campaign strategy. Their campaigns often involve prolonged periods of lateral movement and data collection within compromised networks, indicative of an intent to maximize the value of stolen information. Notable past operations include attacks that have affected high-profile companies in manufacturing and finance sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the identification of Operation Shadow Force as a persistent threat actor targeting South Korean entities, with significant intelligence supporting their use of Shadow Force malware. However, gaps exist regarding their exact motivations and operational TTPs beyond the basics described.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics