러시아와 북한 파트너쉽에 관한 논문을 위장한 APT 공격 (Kimsuky)

2024-09-06 Ahnlab Kimsuky APT attack disguised as a paper on Russia and North Korea partnership

https://asec.ahnlab.com/ko/83026/

Thumbnail for 러시아와 북한 파트너쉽에 관한 논문을 위장한 APT 공격 (Kimsuky)

AhnLab reports a Kimsuky APT campaign targeting domestic users with decoy Word documents themed around Russia and North Korea relations. The attacker used a GitHub repository to host multiple malicious scripts and benign decoy files, with the scripts ultimately stealing user information. The source also notes Run key persistence and additional file attribute and permission changes to support more refined intrusion activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ac68dad3114c469c5d1e81f9dbc59eb0 2024-09-06 2024-09-06
HASH b0e7a8fa1eb5690e7e42fb09c9ee6307 2024-09-06 2024-09-06
HASH e5288ab0f625e498e27178b0d17329f9 2024-09-06 2024-09-06

Related Actors

Related Reports

« Back