공격자 메일에 회신한 경우에 외부 링크로 제공되는 워드문서 (Kimsuky)

2022-07-26 Ahnlab Word documents delivered through external links after replying to attacker emails (Kimsuky)

https://asec.ahnlab.com/ko/37175/

Thumbnail for 공격자 메일에 회신한 경우에 외부 링크로 제공되는 워드문서 (Kimsuky)

AhnLab reported continued Kimsuky distribution of malicious Word documents themed around North Korea-related work, including resume, interim-report, advisory-request, and webinar lures. In one flow, the attacker impersonated a domestic organization and only sent an external download link after the recipient replied positively to the initial email, leading through a credential-harvesting URL and likely document download path. The documents used Korean macro-enable decoy images and VBA macros that created a version.ini script or copied mshta.exe to gtfmon.exe, then attempted to contact asssambly.mywebcommunity[.]org or freunkown1.sportsontheweb[.]net. AhnLab warns that the activity reflects persistent Kimsuky use of socially engineered Word documents and external links against users handling DPRK-related topics.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN freunkown1.sportsontheweb.net 2022-07-26 2022-07-29
HASH 7fe055d5aa72bd50470da61985e12a8a 2022-07-26 2022-07-26
HASH 357ef37979b02b08120895ae5175eb0a 2022-07-26 2022-07-26
URL http://freunkown1.sportsonthewe… 2022-07-26 2022-07-26
URL http://asssambly.mywebcommunity… 2022-07-26 2022-07-26
URL https://accounts.serviceprotect… 2022-07-26 2022-07-26
DOMAIN asssambly.mywebcommunity.org 2022-07-26 2022-07-26
DOMAIN accounts.serviceprotect.eu 2022-07-26 2022-07-26

Related Actors

Related Reports

« Back