김수키(Kimsuky)조직, 21대 국회의원 선거문서로 사칭한 스모크 스크린 APT 공격 수행

2020-04-10 ESTSecurity The Kimsuky organization carried out a smoke screen APT attack disguised as an election document for the 21st National Assembly member.

https://blog.alyac.co.kr/2906

Thumbnail for 김수키(Kimsuky)조직, 21대 국회의원 선거문서로 사칭한 스모크 스크린 APT 공격 수행

ESRC reported another Kimsuky “Smoke Screen” campaign using malicious DOCX files disguised as South Korean National Assembly election and diplomacy-related documents. The documents referenced an external template at saemaeul.mireene[.]com in settings.xml.rels, displayed content-enable prompts, and contacted the same Mireene-hosted infrastructure to retrieve or execute malicious macro content. After execution, the malware created commands under a .NETFramework4.xml filename, registered persistence through a KMSAuto-themed scheduled task, and communicated with report.php and down.php endpoints for further attacker commands and information theft. The source says Kimsuky had been repeatedly targeting South Korean companies and institutions through this campaign in early 2020.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://schemas.openxmlformats.o… 2020-03-20 2023-06-06
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-07-29
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-07-29
DOMAIN saemaeul.mireene.com 2020-04-10 2020-07-29
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-04-10
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-04-10
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-04-10
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-04-10
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-04-10
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-04-10

Related Actors

Related Reports

« Back