논문 심사 사례비 지급으로 위장한 북한發 해킹 공격 주의
2022-10-12 • ESTSecurity • Beware of North Korean hacking attacks disguised as payment for thesis review fees •
ESRC warns of a North Korea-linked campaign targeting professors in aviation, diplomacy, security, and defense with lures disguised as thesis-review requests and honorarium payments. The attackers first approached victims with benign-looking emails, then selectively sent phishing pages or malicious Word documents after recipients responded. The phishing sites impersonated university login portals and delivered legitimate documents after credential entry to reduce suspicion. ESRC links the infrastructure and tactics to the Fake Striker campaign associated with North Korea’s Reconnaissance General Bureau, and warns that academic reviewers and former professors in public office could be exposed to credential and personal-information theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ewha-cloud.epizy.com | 2022-10-12 | 2022-10-12 |