Operation Oceansalt
released on 2018-10-18 @ 02:46:26 PM
We have named this threat Operation Oceansalt based on its similarity to the earlier malware
Seasalt, which is related to earlier Chinese hacking operations. Oceansalt reuses a portion
of code from the Seasalt implant (circa 2010) that is linked to the Chinese hacking group
Comment Crew. Oceansalt appears to have been part of an operation targeting South
Korea, United States, and Canada in a well-focused attack. A variation of this malware has
been distributed from two compromised sites in South Korea.