‘방역 수칙 위반 경찰서 출석요구서’ 등 불안심리 악용한 해킹 공격 주의!

2022-04-07 ESTSecurity Beware of hacking attacks that exploit anxiety, such as ‘police station attendance request for violation of quarantine rules'!

https://blog.alyac.co.kr/4622

Thumbnail for ‘방역 수칙 위반 경찰서 출석요구서’ 등 불안심리 악용한 해킹 공격 주의!

ESRC reported a mass phishing campaign using malicious Word documents named around anxiety-inducing themes such as quarantine-rule police attendance notices and emergency relief application forms. The emails attempted to persuade recipients to enable Office macros, after which the document contacted attacker-controlled C2 infrastructure and installed additional malware. The malware collected host details including username, antivirus product, operating system, and system version, giving attackers reconnaissance data for follow-on activity. ESRC assessed the activity as an extension of a previously reported KRNIC-impersonation campaign and noted detections including Trojan.Downloader.DOC.Gen and Trojan.Agent variants.

« Back