'금성121' APT 조직, 국내 정치사회적 이슈를 악용한 공격 진행중!

2023-09-19 ESTSecurity 'Geumseong 121' APT organization is conducting attacks exploiting domestic political and social issues!

https://alyacofficialblog.tistory.com/5251

Thumbnail for '금성121' APT 조직, 국내 정치사회적 이슈를 악용한 공격 진행중!

ESTsecurity reported that Geumseong121, a North Korea backed APT also tracked as APT37, Group123, RedEyes, and ScarCruft, used domestic political and social issues as lures in large LNK files. One attack impersonated an activist document about Kim Jong Un's Russia visit, showing a decoy HWP file while PowerShell and 182309.bat downloaded word1.jpg from OneDrive. The final stage connected to pCloud with hardcoded token values to collect and transmit files by extension and to download or execute additional payloads. A related oversized LNK lure about National Intelligence Service reform used the same behavior with a PDF decoy and profile32.jpg payload, and ALYac detections included Trojan.Agent.LNK.Gen, Trojan.BAT.Agent, and Trojan.Agent.889859A.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7822e53536c1cf86c3e44e31e77bd088 2023-09-19 2025-05-12
HASH d77c8449f1efc4bfb9ebff496442bbbc 2023-09-19 2025-05-12
HASH a635bd019674b25038cd8f02e15eebd2 2023-09-19 2025-05-12
HASH beeaca6a34fb05e73a6d8b7d2b8c2ee3 2023-09-19 2025-05-12
HASH 7b831f71e3e0dba96c1019b1ca36e013 2023-09-19 2023-09-19
HASH a4156ad86c53339986050df352a8613a 2023-09-19 2023-09-19

Related Actors

Related Reports

« Back