北 해킹 조직의 언론사 위장 스피어 피싱 공격 주의!

2025-08-07 ESTSecurity Warning on spear-phishing attacks by a North Korean hacking group impersonating media organizations

https://alyacofficialblog.tistory.com/5620

Thumbnail for 北 해킹 조직의 언론사 위장 스피어 피싱 공격 주의!

A spear-phishing operation targeted a specific person at a South Korean nonprofit policy research institute by impersonating a domestic media employee during an otherwise plausible column-submission workflow. The attack delivered a password-protected ZIP through a large-file attachment link from a local portal mail service, containing a Chrome-icon LNK file that executed PowerShell and staged scripts in %TEMP% and %APPDATA%. The PowerShell chain fetched a decoy PDF, registered a scheduled task named "MicrorfteguesoftUpdata1logiveKentwuerwtySchule" for 30-minute persistence, and attempted to retrieve additional TXT-based payloads from attacker C2 infrastructure. ESRC assessed the tradecraft as highly similar to typical Kimsuky activity and detected the components as Trojan.Agent.LNK.Gen and Trojan.PowerShell.Agent, with three MD5 hashes provided as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f9221d81b6c672ebebd2e1a1f59ad1cc 2025-08-07 2025-08-07
HASH 08ea68fba0a2bed73b44d962712d0371 2025-08-07 2025-08-07
HASH 8e6298c3b0ed49dc37cc4c9995f4a7c2 2025-08-07 2025-08-07

Related Actors

Related Reports

« Back