The Operation Red Signature Supply Chain Attack
Updated 5 Oct 2026 · Incident date 18 Jul 2018 · vendor binary
South Korean remote support solution - malicious update served 18-31 July 2018 (vendor never named publicly)update.zip served by the vendor's update server, carryi...From 18 to 31 July 2018, attackers used the update server of a South Korean remote support software vendor to deliver the 9002 remote access trojan. The vendor was never named in public. The update file was signed with a valid code-signing certificate stolen from the vendor.
Trend Micro named the campaign Operation Red Signature. The update server sent the malicious file only to certain IP ranges.
What happened
Attackers took over the vendor's update server and sent a malicious update to chosen victims. Trend Micro reports that the update process began at about 13:35 on 18 July 2018, and that the 9002 RAT was active from 18 to 31 July. Trend Micro found the attacks at the end of July, and South Korean media reported them on 6 August 2018.
The update package was named update.zip. It was signed with a valid certificate that the attackers had stolen from the vendor, so Windows showed no warning. The server gave the file only to victims inside target IP ranges. The sources give no list of victims and no vendor name.
The payload was the 9002 RAT. Trend Micro reports that the attackers then downloaded more tools:
- DsGet, DsQuery and SharpHound to map Active Directory.
- A custom Mimikatz (
m.exe) and a SQL password dumper (ssms.exe). - A PlugX variant (
printdat.dll). - An IIS 6 WebDAV exploit tool (
w.exe) for CVE-2017-7269, and WebBrowserPassView.
Trend Micro dates the first sign of the same stolen certificate to 8 April 2018, when a different backdoor named ShiftDoor was signed with it. The goals were information gathering and persistence, with a focus on web servers and databases, according to BleepingComputer.
Vigilance compares the version you trust with the new one. A vendor update that now holds a new payload is the kind of change it reports. See the scan block below.
Affected versions
- A malicious update of a South Korean remote support product, served from 18 to 31 July 2018.
The vendor and the product version are not named in the sources, so this page lists no version.
Indicators of compromise
- Servers:
207.148.94.157(distribution) and66.42.37.101(command, for the 9002 RAT and the PlugX variant). - URLs:
hxxp://207.148.94.157/update/rcv50/update.zip,.../file000.zip,.../file001.zip, and/aio.exe,/smb.exe,/m.ex_,/w,/Web.ex_. - SHA-256 of ShiftDoor:
0703a917aaa0630ae1860fb5fb1f64f3cfb4ea8c57eac71c2b0a407b738c4e19. - SHA-256 of
printdat.dll:9415ca80c51b2409a88e26a9eb3464db636c2e27f9c61e247d15254e6fbb31eb. - SHA-256 of
rcview40u.dll:bcfacc1ad5686aee3a9d8940e46d32af62f8e1cd1631653795778736b67b6d6e. - SHA-256 of
m.exe:a3a1b1cf29a8f38d05b4292524c3496cb28f78d995dfb0a9aef7b2f949ac278b. - Other file names:
aio.exe,sharphound.exe,ssms.exe,w.exe,Web.exe,smb.exe,rcview.log.
See the Trend Micro report for the full hash table.
How to check
Search proxy and firewall logs for the two addresses, and search disks for the tool names. In PowerShell:
Get-ChildItem C:\ -Recurse -Include printdat.dll,rcview40u.dll,rcview.log,ssms.exe,sharphound.exe -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256
Compare each hash with the report. A ssms.exe or printdat.dll file outside a normal SQL Server or printer install needs a close look.
What to do now
- Find out if any machine took a remote support update between 18 and 31 July 2018.
- If you find an indicator, isolate the host and review the whole network. The attackers mapped Active Directory and dumped passwords.
- Reset passwords and keys that were used on those hosts and on servers they can reach.
- Block the two addresses.
- Trend Micro advises tighter control of third-party tools, least privilege, network segmentation and application control.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 16 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE South.exe It reads saved passwords and access keys.
Frequently asked questions
Which remote support vendor was hit in Operation Red Signature?
The sources never name the vendor. They only say it was a South Korean remote support solutions provider whose update server the attackers compromised.
How did Operation Red Signature get past security warnings?
The malicious update was signed with a valid code-signing certificate that the attackers stole from the vendor. Windows showed no warning.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.