국내 타깃형 APT공격그룹 - 김수키(Kimsuky)

2020-03-31 Igloo Domestic targeting APT attack group - Kimsuky

https://www.igloo.co.kr/security-information/%ec%95%8c%ec%95%84%eb%b3%b4%ec%9e%a1-series-%ea%b5%ad%eb%82%b4-%ed%83%80%ea%b9%83%ed%98%95-apt%ea%b3%b5%ea%b2%a9%ea%b7%b8%eb%a3%b9-%ea%b9%80%ec%88%98%ed%82%a4kimsuky/

Thumbnail for 국내 타깃형 APT공격그룹 - 김수키(Kimsuky)

IGLOO profiles Kimsuky as a suspected North Korean group focused on domestic Korean targets for information collection and social disruption, citing the 2014 KHNP incident and continued use of social-engineering themes tied to Korean and North Korea-related issues. The analyzed 2020 samples show a shift from earlier HWP-heavy activity toward Windows executable droppers disguised as document files, including COVID-19-themed macro lures and PE files with document icons and deceptive extensions. The droppers open decoy documents while creating batch files, dropping malicious DLLs, injecting into explorer.exe, and using registry locations for persistence across reboot. The report’s CTI value is its mapping of Kimsuky TTPs against MITRE ATT&CK and its evidence that convincing document-themed lures remained central even as payload formats changed.

Related Actors

Related Reports

« Back