Brave Prince

MITRE ATT&CK: S0252 View on attack.mitre.org

Aliases: Brave Prince

First seen
2017-12-01 00:00:00
Malware type
rat, spyware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:18:44

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:kr

Context

Brave Prince is a Korean-language implant that was first observed in the wild in December 2017. It contains similar code and behavior to Gold Dragon, and was seen along with Gold Dragon and RunningRAT in operations surrounding the 2018 Pyeongchang Winter Olympics.

Detection coverage

  • 240 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Process Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Used by threat actors

Reports & references

  • McAfee — Gold Dragon Widens Olympics Malware Attacks Gains Permanent Presence On Victims Systems (report)
  • MITRE ATT&CK — S0252 (report)

External references