김수키(Kimsuky) 그룹, 러시아 외무부를 타겟으로 공격 진행중!
2022-08-26 • ESTSecurity • Kimsuky group is conducting attacks targeting the Russian Ministry of Foreign Affairs! •
Kimsuky activity targeted the Russian Ministry of Foreign Affairs through email, using what ESRC assessed as a previously stolen Russian consulate account in Shenyang to attack the Russian consulate in Japan. The lure impersonated an embassy accounting department and claimed to provide embassy information for a money transfer. The attached PowerPoint content included a file about Pyongyang-Moscow talks on Donbass, while the malicious component used a PowerPoint Add-In format with VBA rather than a standard macro-disabled .ppt or .pptx file. The macro contained a VBS file registered with Task Scheduler to run every five minutes and wait for commands from a C2 server. The report highlights hxxp://gg1593.c1.biz/dn.php and MD5 DAE0EFD29230FEAB95F46EE20030A425 as indicators for this campaign.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 185.176.43.106 | 2021-03-10 | 2024-11-08 |
| HASH | dae0efd29230feab95f46ee20030a425 | 2022-08-26 | 2024-09-05 |
| DOMAIN | gg1593.c1.biz | 2022-08-26 | 2024-09-05 |
| URL | http://gg1593.c1.biz/dn.php | 2022-08-26 | 2023-05-31 |