김수키(Kimsuky) 그룹, 러시아 외무부를 타겟으로 공격 진행중!

2022-08-26 ESTSecurity Kimsuky group is conducting attacks targeting the Russian Ministry of Foreign Affairs!

https://blog.alyac.co.kr/4892

Thumbnail for 김수키(Kimsuky) 그룹,  러시아 외무부를 타겟으로 공격 진행중!

Kimsuky activity targeted the Russian Ministry of Foreign Affairs through email, using what ESRC assessed as a previously stolen Russian consulate account in Shenyang to attack the Russian consulate in Japan. The lure impersonated an embassy accounting department and claimed to provide embassy information for a money transfer. The attached PowerPoint content included a file about Pyongyang-Moscow talks on Donbass, while the malicious component used a PowerPoint Add-In format with VBA rather than a standard macro-disabled .ppt or .pptx file. The macro contained a VBS file registered with Task Scheduler to run every five minutes and wait for commands from a C2 server. The report highlights hxxp://gg1593.c1.biz/dn.php and MD5 DAE0EFD29230FEAB95F46EE20030A425 as indicators for this campaign.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 185.176.43.106 2021-03-10 2024-11-08
HASH dae0efd29230feab95f46ee20030a425 2022-08-26 2024-09-05
DOMAIN gg1593.c1.biz 2022-08-26 2024-09-05
URL http://gg1593.c1.biz/dn.php 2022-08-26 2023-05-31

Related Actors

Related Reports

« Back