김수키(Kimsuky) 조직 소행 추정 ‘대북 분야 국책연구기관’ 사칭 스피어피싱 공격 발견
2019-10-17 • ESTSecurity • A spear phishing attack was discovered impersonating a ‘national research institute in the field of North Korea', believed to be the work of the Kimsuky organization. •
A spear-phishing email impersonated the Korea Institute for National Unification and delivered a malicious HWP document disguised as an expert consultation request on the U.S.–ROK alliance and Korea-China relations. If opened, the document infected the system, collected host information, recently opened document lists, and running process data, then left the PC waiting for further attacker commands. The malware also disguised components as legitimate modules from domestic software and security companies. ESRC assessed the malware-building techniques and attack style as largely matching prior Kimsuky activity, while noting the actor attribution as an assessment based on those similarities.