钓鱼之王 —— Kimsuky近期以多个话题针对韩国的鱼叉式钓鱼攻击活动分析
2022-07-25 • Qianxin • King of Phishing: Analysis of recent Kimsuky spear-phishing attacks against South Korea using multiple themes •
Qianxin attributes with medium confidence a set of spear-phishing attacks against South Korean targets to Kimsuky, noting the group's focus on defense, education, energy, government, healthcare, and think tanks. The campaign used HWP lure documents themed around North Korean defector advisory surveys, Korea Policy Broadcasting invitations, and North Korea COVID-19 analysis to induce user interaction and execute embedded OLE or EPS content. The execution chain dropped temporary files, ran PowerShell, injected MSF-generated shellcode into legitimate Windows processes such as help.exe or winhlp32.exe, and used fileless follow-on loading to reduce detection. One sample used mshta.exe and a scheduled task named EstSoft\Alcap\Report to periodically contact C2, parse returned commands, execute them via cmd.exe, and post results back. Reported indicators include MD5 hashes such as 905745E2A196D7F8D7C2F9547F5B9E67 and infrastructure including hanainternational.net and work3.b4a.app.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 905745e2a196d7f8d7c2f9547f5b9e67 | 2022-07-25 | 2022-09-03 |
| HASH | 8b9ea99a52c995d299e25df2ab24175d | 2022-07-25 | 2022-07-25 |
| HASH | a5e4d92c27fb4f8308f77a3833451801 | 2022-07-25 | 2022-07-25 |
| HASH | 29307065fc17ba422c93b790ac723a90 | 2022-07-25 | 2022-07-25 |
| URL | https://work3.b4a.app/download.… | 2022-06-20 | 2022-07-25 |
| URL | http://hanainternational.net/ed… | 2022-06-01 | 2022-07-25 |
| DOMAIN | hanainternational.net | 2022-05-09 | 2022-07-25 |