금성121' 그룹의 '남북이산가족찾기 전수조사' 사칭 이메일 주의

2018-07-04 ESTSecurity Beware of emails purporting to be from the ‘Geumseong 121' group, which purports to be a ‘complete survey to find separated families from North and South Korea'

http://blog.alyac.co.kr/1767

Thumbnail for 금성121' 그룹의 '남북이산가족찾기 전수조사' 사칭 이메일 주의

Operation Mystery Egg is described as an APT campaign by the Geumseong121 group that impersonated South Korea’s Ministry of Unification and used a lure about a government survey on separated North-South families. Instead of attaching an executable or HWP file directly, the attackers sent an HTML attachment made to look like a protected security-mail attachment, creating a different spear-phishing delivery vector. The campaign also involved an HWP document vulnerability with added PostScript reverse obfuscation, and an encrypted payload hidden in the document stream that communicated covertly with Dropbox-based C2 after shellcode execution. The excerpt notes Russian-language code fragments in the IOCs and assesses them as likely false-flag artifacts intended to confuse attribution analysis. The activity matters because it combines Korean government-themed social engineering, document exploitation, cloud C2, and deception tradecraft against South Korean targets.

Related Actors

Related Reports

« Back