다양한 주제의 보도자료를 사칭한 Kimsuky 공격시도

2022-05-18 Ahnlab Attempted Kimsuky attacks impersonating press releases on various topics

https://asec.ahnlab.com/ko/34383/

Thumbnail for 다양한 주제의 보도자료를 사칭한 Kimsuky 공격시도

AhnLab reported Kimsuky-linked attack attempts using malware disguised as press releases on topics including North Korea’s COVID-19 acknowledgement and other Korean public-announcement themes. The .NET executables used HWP or Word document icons, dropped a Roamingtemp VBScript under AppData, launched it with wscript.exe, and downloaded decoy documents so victims would see normal files while malicious activity continued. The script contacted mc.pzs[.]kr paths and resembled VBS code previously seen in Kimsuky activity impersonating requests for North Korea-related manuscripts. Follow-on behavior created an OfficeAppManifest XML file under Microsoft Windows Templates, registered a service named Microsoft, changed browser-related settings, and attempted to run PowerShell that retrieved content from lib.php on the same infrastructure. The report lists downloader and MSILKrypt detections plus multiple sample hashes and URLs, making the campaign useful for identifying document-disguise execution chains and mc.pzs[.]kr infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN mc.pzs.kr 2022-05-18 2023-11-01
HASH 5573953bf4dafa96877dacf3435db228 2022-05-18 2022-05-18
HASH d6730f10a839d128e94b5aa05d9fb1ec 2022-05-18 2022-05-18
HASH 94fdc2115ce7f4ab0234a1e26901cb1c 2022-05-18 2022-05-18
HASH 34b7356722b992992f5382b0761466bc 2022-05-18 2022-05-18
HASH a15c386db0a3d0d208042d0982f21f37 2022-05-18 2022-05-18
HASH 3ad7a29a1f661034da0b3779a4046849 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18
URL http://mc.pzs.kr/themes/mobile/… 2022-05-18 2022-05-18

Related Actors

Related Reports

« Back