디지털 자산 지갑 서비스 고객센터로 위장한 北 연계 APT 공격 발견

2022-02-16 ESTSecurity North Korea-Linked APT Attack Found Disguised as a Digital Asset Wallet Service Customer Center

https://blog.alyac.co.kr/4501

Thumbnail for 디지털 자산 지갑 서비스 고객센터로 위장한 北 연계 APT 공격 발견

ESRC identified a malicious Word document distributed as a Klip digital asset wallet customer-center notice, using the filename '[Klip Customer Center] Wrong Token Transfer Resolution Guide.doc'. The document used protected-content social engineering to persuade users to enable macros, then dropped an XML-formatted file and attempted to contact command-and-control infrastructure. ESRC attributed the activity to the Smoke Screen campaign associated with Thallium, also known as Kimsuky, and noted that the C2 was unavailable during analysis. The report provides two defanged C2 URLs under asenal.medianewsonline.com and states that Alyac detects the file as Trojan.Downloader.DOC.Gen.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://asenal.medianewsonline.c… 2022-02-16 2022-02-16
URL http://asenal.medianewsonline.c… 2022-02-16 2022-02-16
DOMAIN asenal.medianewsonline.com 2022-02-16 2022-02-16

Related Actors

Related Reports

« Back