북한이탈주민(탈북민) 자문위원대상 의견수렴 설문지 위장 北 연계 해킹 주의
2022-05-09 • ESTSecurity • Beware of North Korea-linked hacking disguised as a questionnaire to collect opinions from North Korean defectors (defectors) and advisory committee members •
ESTsecurity ESRC identified a North Korea-linked HWP document attack disguised as a survey for North Korean defector advisory committee members. The lure abused current news about anti-North Korea leaflet launches and displayed a fake HWP version message to persuade the user to click. Once opened, embedded OLE content executed a batch file and PowerShell commands that attempted communication with a domestic Korean server. The activity used task scheduler conditions to hide C2 communication and impersonated ESTsoft-related software, with overlaps to an earlier phishing case impersonating the UN Human Rights Office. ESRC assessed the HWP technique and command tactics as consistent with previous North Korea-linked cyber operations and shared threat intelligence with KISA and other authorities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | hanainternational.net | 2022-05-09 | 2022-07-25 |