Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Yanbian Gang

Description

RiskIQ characterizes the Yanbian Gang as a group that targeted South Korean Android mobile banking customers since 2013 with malicious Android apps purporting to be from major banks, namely Shinhan Savings Bank, Saemaul Geumgo, Shinhan Finance, KB Kookmin Bank, and NH Savings Bank.

AI Analysis

· 1 week ago

Executive Summary

The Yanbian Gang poses a significant threat to South Korean mobile banking users through the distribution of malicious Android apps since 2013. Their primary focus has been on targeting major financial institutions, aiming to compromise customer accounts for financial gain.

Goals & Targeting

The Yanbian Gang's strategic goals are centered around financial gain through unauthorized access to customer accounts in the banking sector. Their targeting profile is specifically focused on South Korea due to its high reliance on mobile banking services, which makes it a prime target for financial fraud. The group typically targets individuals who use popular mobile banking apps, exploiting trust in well-known financial institutions to deliver malicious payloads.

Enhanced Description

The Yanbian Gang is a cybercriminal group known for its sophisticated attacks against South Korean Android mobile banking customers. Since 2013, the group has specialized in creating and distributing malicious apps that appear to be legitimate financial services from major banks such as Shinhan Savings Bank, KB Kookmin Bank, and NH Savings Bank. These apps are designed to steal sensitive user data, including login credentials and transaction information. The gang's operations primarily target mobile users due to the high adoption of mobile banking in South Korea, making it an lucrative target for financial exploitation. Their ability to consistently evade detection highlights their technical proficiency in creating convincing phishing campaigns and malware distribution mechanisms.

Key Capabilities

  • Social engineering via SMS and messaging applications
  • Development and distribution of malicious Android apps
  • Establishment of command-and-control (C2) infrastructure for stolen data exfiltration

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Initial Access

ATT&CK Techniques

T1078.001
T1566.004
T1059.003

Software / Tooling

Yanba Android Malware

Campaigns & Victims

The Yanbian Gang has been active since 2013, consistently targeting South Korean mobile banking users through phishing campaigns and malicious app distribution. Their campaigns often involve sending deceptive SMS messages or links to fake bank websites, tricking users into downloading malware-laced apps. Notable operations include multiple waves of attacks against major banks, with the goal of stealing user credentials for unauthorized transactions.

IOC Patterns

  • Spear-phishing campaigns targeting mobile banking users via SMS
  • Distribution of Android APK files mimicking legitimate financial institution apps
  • Command-and-control communication over hardcoded domains

Recommended Actions

  • Implement rigorous app verifications and threat detection on mobile banking platforms.
  • Educate users on recognizing suspicious messages or links claiming to be from banks.
  • Monitor for unusual account activities indicative of unauthorized access.
  • Conduct regular penetration testing to identify vulnerabilities in mobile banking systems.

Suggested Tags

APT
Mobile Threat
Financial Sector
South Korea

Confidence Assessment

High confidence, given the consistent targeting patterns and known malicious activity since 2013. Limited visibility into their specific malware frameworks beyond basic Android-based threats remains a key information gap.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
APT
Mobile Threat
Financial Sector
South Korea

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.