금성121' 그룹의 '남북이산가족찾기 전수조사' 사칭 이메일 주의
2018-07-04 • ESTSecurity • Beware of emails purporting to be from the ‘Geumseong 121' group, which purports to be a ‘complete survey to find separated families from North and South Korea' •
Operation Mystery Egg is described as an APT campaign by the Geumseong121 group that impersonated South Korea’s Ministry of Unification and used a lure about a government survey on separated North-South families. Instead of attaching an executable or HWP file directly, the attackers sent an HTML attachment made to look like a protected security-mail attachment, creating a different spear-phishing delivery vector. The campaign also involved an HWP document vulnerability with added PostScript reverse obfuscation, and an encrypted payload hidden in the document stream that communicated covertly with Dropbox-based C2 after shellcode execution. The excerpt notes Russian-language code fragments in the IOCs and assesses them as likely false-flag artifacts intended to confuse attribution analysis. The activity matters because it combines Korean government-themed social engineering, document exploitation, cloud C2, and deception tradecraft against South Korean targets.