北 해킹 조직, 한미연합훈련 기간 중 방위산업체 대상 공격

2022-08-25 ESTSecurity North Korean hacking organization attacks defense industry companies during ROK-U.S. joint military exercises

https://blog.alyac.co.kr/4890

Thumbnail for 北 해킹 조직, 한미연합훈련 기간 중 방위산업체 대상 공격

ESRC reported multiple attacks against South Korean defense-industry organizations during the ROK-U.S. joint military exercises that began on August 22, 2022. The activity used executable lures disguised as IP and MAC address lookup tools, double-extension JSE/VBS scripts, PIF files mimicking shortcut icons, and phishing pages imitating internal defense-company login services. Malware samples showed similar patterns and communicated with the same U.S.-hosted IP address, 216.189.154[.]6, while some lures appeared to reuse internal defense-sector documents protected by a Korean DRM solution. ESRC attributed the activity to Kimsuky/Thallium, linked to North Korea's Reconnaissance General Bureau, and assessed it as part of the ongoing Blue Estimate campaign targeting defense, aerospace, government-adjacent organizations, and related private experts.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 216.189.154.6 2022-08-25 2024-03-12

Related Actors

Related Reports

« Back