북한이탈주민(탈북민) 자문위원대상 의견수렴 설문지 위장 北 연계 해킹 주의

2022-05-09 ESTSecurity Beware of North Korea-linked hacking disguised as a questionnaire to collect opinions from North Korean defectors (defectors) and advisory committee members

https://blog.alyac.co.kr/4702

Thumbnail for 북한이탈주민(탈북민) 자문위원대상 의견수렴 설문지 위장 北 연계 해킹 주의

ESTsecurity ESRC identified a North Korea-linked HWP document attack disguised as a survey for North Korean defector advisory committee members. The lure abused current news about anti-North Korea leaflet launches and displayed a fake HWP version message to persuade the user to click. Once opened, embedded OLE content executed a batch file and PowerShell commands that attempted communication with a domestic Korean server. The activity used task scheduler conditions to hide C2 communication and impersonated ESTsoft-related software, with overlaps to an earlier phishing case impersonating the UN Human Rights Office. ESRC assessed the HWP technique and command tactics as consistent with previous North Korea-linked cyber operations and shared threat intelligence with KISA and other authorities.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hanainternational.net 2022-05-09 2022-07-25

Related Reports

« Back