금성121' 조직, 북한 선교 학교 신청서 사칭으로 APT 공격

2019-06-15 ESTSecurity ‘Geumseong 121' organization attacks APT by impersonating a North Korean missionary school application form

https://blog.alyac.co.kr/2363

Thumbnail for 금성121' 조직, 북한 선교 학교 신청서 사칭으로 APT 공격

ESRC attributed a malicious HWP document disguised as a 17th North Korea Mission School application form to the Geumseong121 threat group. The file contained embedded PostScript in its BinData stream and XOR-encrypted shellcode that loaded a final binary into label.exe or sort.exe. The payload attempted command-and-control through a Dropbox token and API commands, while the document metadata reused a User1 account observed in earlier Geumseong121 operations. The archive preserves the HWP hash and Exploit.HWP.Agent detection context for defenders.

Related Actors

Related Reports

« Back