국회입법조사처 사칭하여 '국방·외교·안보'분야 교수 해킹을 시도하는 北 연계 해킹공격 주의!
2022-06-29 • ESTSecurity • Beware of North Korea-linked hacking attacks that impersonate the National Assembly Research Service and attempt to hack professors in the fields of ‘defense, diplomacy, and security'! •
ESRC reported a North Korea-linked phishing campaign impersonating South Korea’s National Assembly Research Service and targeting professors in defense, diplomacy, security, and politics. The operators first sent consultation-request emails that performed no malware action but identified recipients who replied; only responsive targets then received a follow-up email with a malicious document attachment. Opening the lure led victims to a fake large-file download page and then to a credential-harvesting page, after which the site delivered a normal Word file to conceal the compromise. ESRC tied the infrastructure to 118.36.192[.]211 and related naverccrp[.]com lookalike domains previously used in phishing.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 118.36.192.211 | 2022-06-29 | 2025-03-04 |
| DOMAIN | m.naverccrp.com | 2022-06-29 | 2022-06-29 |
| DOMAIN | nca.naverccrp.com | 2022-06-29 | 2022-06-29 |
| DOMAIN | xn--nid-mo0a.naverccrp.com | 2022-06-29 | 2022-06-29 |