김수키 조직, 워터링 홀 개시 '오퍼레이션 로우 킥(Operation Low Kick)'

2019-03-21 ESTSecurity Kim Suki's organization begins watering hole 'Operation Low Kick'

https://blog.alyac.co.kr/2209

Thumbnail for 김수키 조직, 워터링 홀 개시 '오퍼레이션 로우 킥(Operation Low Kick)'

ESRC reported a March 2019 watering-hole campaign against South Korean public and private policy sites and a reunification research organization visited by defense, diplomacy and North Korea-focused researchers. The intrusions injected obfuscated VBS/JavaScript exploiting CVE-2018-8174, launched svchost.exe, downloaded shellcode disguised as image files, and injected a decoded module into userinit.exe. The final malware collected system information, logged keystrokes, and attempted to steal document data such as HWP, DOC and PDF files. ESRC associated the infrastructure, including mail.membercp.net and redirects to hanmail.membercp.net, with Kimsuky activity and named the campaign Operation Low Kick.

Related Actors

Related Reports

« Back