Seo
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias Seo is a 31‑year‑old individual from South Korea who came to law‑enforcement attention in 2014 after purchasing the personal information of approximately 25 million people from a Korean‑Chinese source. The data acquired included names, resident registration numbers, Internet IDs and passwords, which Seo then used to gain unauthorized access to accounts on Naver, the country’s largest web portal. By exploiting these credentials, Seo sent spam and illicit emails to the compromised account holders, generating an estimated illegal profit of 160 million won, equivalent to about $148 000. Police also apprehended a self‑taught programmer surnamed Hong who had created automated hacking tools that automatically entered IDs and passwords to log into Naver accounts, and these tools were supplied to Seo. In addition to Hong, three of Seo’s accomplices were indicted without detention, and the investigation was expanded to include 86 other individuals who had purchased the hacking programs developed by Hong.
The actor’s activities were directed at South Korean internet users, specifically targeting the user base of a major domestic web service, with the apparent strategic objective of financial gain through the distribution of spam and fraudulent emails. The observed tactics involved the use of stolen credential datasets combined with credential‑stuffing automation, rather than the deployment of traditional malware families or exploitation of software vulnerabilities. This approach relied on the availability of personal data and the ability to script mass login attempts, highlighting a TTP theme centered on credential abuse and automated access tools. No public attribution links Seo to any state‑sponsored group or larger criminal consortium; the case was treated as an individual‑driven criminal enterprise with a network of collaborators who facilitated the development and distribution of the hacking utilities.
The most notable publicly reported operation associated with Seo occurred in August 2014 when the stolen data was used to breach Naver accounts, leading to the widespread spam campaign that prompted law‑enforcement action and public advisories from Naver urging users to change passwords regularly. The incident underscored the broader challenge of readily accessible personal information in the region and resulted in legal proceedings against the primary actors and their associates, while authorities continued to investigate the wider circle of individuals who had acquired the automated hacking tools. The case remains a representative example of how credential theft coupled with simple automation can be monetized at scale within a specific national internet ecosystem.
Incidents
Attributed incidents are available to members.
1 incident