국립외교원 구글 설문지로 위장한 北 연계 해킹 공격 등장!
2022-10-26 • ESTSecurity • A North Korean-linked hacking attack disguised as a Google questionnaire from the National Diplomatic Academy appears! •
ESRC reports a North Korea-linked phishing campaign that impersonated South Korea’s Korea National Diplomatic Academy and abused Google Forms as a lure. The attackers used diplomatic or policy-themed content to persuade targets to open a fake survey or document workflow, then directed them toward credential-harvesting infrastructure. The campaign fits the broader pattern of North Korean social-engineering operations against foreign-policy, security, and academic personnel. ESRC recommends careful URL verification and caution with survey or document links received from unexpected senders.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | accounts.qocple.epizy.com | 2022-10-26 | 2023-04-18 |
| DOMAIN | epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | docxooqle.epizy.com | 2022-10-26 | 2022-10-26 |