군사안보 월간지(4월호) 위장한 악성 워드문서 유포 중

2021-04-02 Ahnlab A malicious word document disguised as a military security monthly magazine (April issue) is being distributed.

https://asec.ahnlab.com/ko/21746/

Thumbnail for 군사안보 월간지(4월호) 위장한 악성 워드문서 유포 중

AhnLab ASEC observed malicious Word documents disguised as the April issue of a military-security monthly publication, continuing a pattern of North Korea-themed document malware. The DOCX files used protected content and an external relationship in the document XML to reach a remote address and download additional content. The lure appears aimed at recipients working on North Korea-related matters, while the source notes that a legitimate version of the publication was distributed as a PDF. AhnLab detected the files as Downloader/DOC.External and warned users about increased social-engineering attacks using DPRK-themed document content.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN beilksa.scienceontheweb.net 2021-04-02 2023-10-30
URL http://beilksa.scienceontheweb.… 2021-04-02 2021-09-01

Related Reports

« Back