문서파일 취약점 공격과 한국 가상화폐 거래자 대상 공격간의 연관성 분석

2017-12-15 ESTSecurity Analysis of the correlation between document file vulnerability attacks and attacks targeting Korean virtual currency traders

http://blog.alyac.co.kr/1446

Thumbnail for 문서파일 취약점 공격과 한국 가상화폐 거래자 대상 공격간의 연관성 분석

ESRC links several Korea-focused spear-phishing incidents through shared operational traces rather than naming a specific actor. In mid-2017, a malicious HWP document exploit targeted a South Korean person active in North Korea-related work, and the document metadata reused accounts such as “SEIKO,” “Lion,” and artifacts previously seen in attacks against South Korean power-sector and research targets. The same sending IP and message-ID domain later appeared in a December 2017 phishing operation impersonating a Korean portal account-protection page and aimed mainly at cryptocurrency exchange-related members. The report argues that infrastructure and mail-tracking overlaps suggest the operator that had targeted South Korean security, unification, defense, finance, and North Korea-related communities was also shifting toward cryptocurrency-related victims.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN eng.co.kr 2017-12-15 2017-12-15

Related Reports

« Back