'금성121' APT 조직, 국내 정치사회적 이슈를 악용한 공격 진행중!
2023-09-19 • ESTSecurity • 'Geumseong 121' APT organization is conducting attacks exploiting domestic political and social issues! •
ESTsecurity reported that Geumseong121, a North Korea backed APT also tracked as APT37, Group123, RedEyes, and ScarCruft, used domestic political and social issues as lures in large LNK files. One attack impersonated an activist document about Kim Jong Un's Russia visit, showing a decoy HWP file while PowerShell and 182309.bat downloaded word1.jpg from OneDrive. The final stage connected to pCloud with hardcoded token values to collect and transmit files by extension and to download or execute additional payloads. A related oversized LNK lure about National Intelligence Service reform used the same behavior with a PDF decoy and profile32.jpg payload, and ALYac detections included Trojan.Agent.LNK.Gen, Trojan.BAT.Agent, and Trojan.Agent.889859A.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7822e53536c1cf86c3e44e31e77bd088 | 2023-09-19 | 2025-05-12 |
| HASH | d77c8449f1efc4bfb9ebff496442bbbc | 2023-09-19 | 2025-05-12 |
| HASH | a635bd019674b25038cd8f02e15eebd2 | 2023-09-19 | 2025-05-12 |
| HASH | beeaca6a34fb05e73a6d8b7d2b8c2ee3 | 2023-09-19 | 2025-05-12 |
| HASH | 7b831f71e3e0dba96c1019b1ca36e013 | 2023-09-19 | 2023-09-19 |
| HASH | a4156ad86c53339986050df352a8613a | 2023-09-19 | 2023-09-19 |