김수키(Kimsuky)조직, 21대 국회의원 선거문서로 사칭한 스모크 스크린 APT 공격 수행
2020-04-10 • ESTSecurity • The Kimsuky organization carried out a smoke screen APT attack disguised as an election document for the 21st National Assembly member. •
ESRC reported another Kimsuky “Smoke Screen” campaign using malicious DOCX files disguised as South Korean National Assembly election and diplomacy-related documents. The documents referenced an external template at saemaeul.mireene[.]com in settings.xml.rels, displayed content-enable prompts, and contacted the same Mireene-hosted infrastructure to retrieve or execute malicious macro content. After execution, the malware created commands under a .NETFramework4.xml filename, registered persistence through a KMSAuto-themed scheduled task, and communicated with report.php and down.php endpoints for further attacker commands and information theft. The source says Kimsuky had been repeatedly targeting South Korean companies and institutions through this campaign in early 2020.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://schemas.openxmlformats.o… | 2020-03-20 | 2023-06-06 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-07-29 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-07-29 |
| DOMAIN | saemaeul.mireene.com | 2020-04-10 | 2020-07-29 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-04-10 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-04-10 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-04-10 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-04-10 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-04-10 |
| URL | http://saemaeul.mireene.com/ski… | 2020-04-10 | 2020-04-10 |