RiskIQ characterizes the Yanbian Gang as a group that targeted South Korean Android mobile banking customers since 2013 with malicious Android apps purporting to be from major banks, namely Shinhan Savings Bank, Saemaul Geumgo, Shinhan Finance, KB Kookmin Bank, and NH Savings Bank.
Executive Summary
The Yanbian Gang poses a significant threat to South Korean mobile banking users through the distribution of malicious Android apps since 2013. Their primary focus has been on targeting major financial institutions, aiming to compromise customer accounts for financial gain.
Goals & Targeting
The Yanbian Gang's strategic goals are centered around financial gain through unauthorized access to customer accounts in the banking sector. Their targeting profile is specifically focused on South Korea due to its high reliance on mobile banking services, which makes it a prime target for financial fraud. The group typically targets individuals who use popular mobile banking apps, exploiting trust in well-known financial institutions to deliver malicious payloads.
Enhanced Description
The Yanbian Gang is a cybercriminal group known for its sophisticated attacks against South Korean Android mobile banking customers. Since 2013, the group has specialized in creating and distributing malicious apps that appear to be legitimate financial services from major banks such as Shinhan Savings Bank, KB Kookmin Bank, and NH Savings Bank. These apps are designed to steal sensitive user data, including login credentials and transaction information. The gang's operations primarily target mobile users due to the high adoption of mobile banking in South Korea, making it an lucrative target for financial exploitation. Their ability to consistently evade detection highlights their technical proficiency in creating convincing phishing campaigns and malware distribution mechanisms.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Yanbian Gang has been active since 2013, consistently targeting South Korean mobile banking users through phishing campaigns and malicious app distribution. Their campaigns often involve sending deceptive SMS messages or links to fake bank websites, tricking users into downloading malware-laced apps. Notable operations include multiple waves of attacks against major banks, with the goal of stealing user credentials for unauthorized transactions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence, given the consistent targeting patterns and known malicious activity since 2013. Limited visibility into their specific malware frameworks beyond basic Android-based threats remains a key information gap.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics