北 해킹 조직의 언론사 위장 스피어 피싱 공격 주의!
2025-08-07 • ESTSecurity • Warning on spear-phishing attacks by a North Korean hacking group impersonating media organizations •
A spear-phishing operation targeted a specific person at a South Korean nonprofit policy research institute by impersonating a domestic media employee during an otherwise plausible column-submission workflow. The attack delivered a password-protected ZIP through a large-file attachment link from a local portal mail service, containing a Chrome-icon LNK file that executed PowerShell and staged scripts in %TEMP% and %APPDATA%. The PowerShell chain fetched a decoy PDF, registered a scheduled task named "MicrorfteguesoftUpdata1logiveKentwuerwtySchule" for 30-minute persistence, and attempted to retrieve additional TXT-based payloads from attacker C2 infrastructure. ESRC assessed the tradecraft as highly similar to typical Kimsuky activity and detected the components as Trojan.Agent.LNK.Gen and Trojan.PowerShell.Agent, with three MD5 hashes provided as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f9221d81b6c672ebebd2e1a1f59ad1cc | 2025-08-07 | 2025-08-07 |
| HASH | 08ea68fba0a2bed73b44d962712d0371 | 2025-08-07 | 2025-08-07 |
| HASH | 8e6298c3b0ed49dc37cc4c9995f4a7c2 | 2025-08-07 | 2025-08-07 |