금성121' 조직, 북한 선교 학교 신청서 사칭으로 APT 공격
2019-06-15 • ESTSecurity • ‘Geumseong 121' organization attacks APT by impersonating a North Korean missionary school application form •
ESRC attributed a malicious HWP document disguised as a 17th North Korea Mission School application form to the Geumseong121 threat group. The file contained embedded PostScript in its BinData stream and XOR-encrypted shellcode that loaded a final binary into label.exe or sort.exe. The payload attempted command-and-control through a Dropbox token and API commands, while the document metadata reused a User1 account observed in earlier Geumseong121 operations. The archive preserves the HWP hash and Exploit.HWP.Agent detection context for defenders.