북한 의심 APT 공격에 대한 Kaspersky 의 분석 정리

2013-09-12 Kaspersky Summary of Kaspersky's analysis of suspected North Korean APT attacks

https://www.dailysecu.com/bbs/download.php?table=bbs_10&savefilename=bbs_10_1040_2834.pdf&filename=%EB%B6%81%ED%95%9C%EC%9D%98%EC%8B%ACAPT%EA%B3%B5%EA%B2%A9%20%EC%9E%90%EB%A3%8C%20%EB%B6%84%EC%84%9D.pdf

Attachments

북한의심APT공격_자료_분석.pdf (753 KB)

Kimsuky Operation is described as a suspected North Korea-linked cyber-espionage campaign targeting South Korean organizations including the Sejong Institute, KIDA, the Ministry of Unification, Hyundai Marine & Fire Insurance, and a reunification-focused civic group. Kaspersky's attribution indicators included Korean-language strings in the malware compile path, targeting aligned with North Korean interests, collection of HWP documents, attempts to disable Windows and AhnLab firewalls, a recipient account registered under the Korean name Kim Suk-hyang, and operator IPs from China's Jilin and Liaoning regions near North Korea. The malware chain loads an encrypted library, uses Metasploit Win7Elevate-style injection into explorer.exe, disables firewall/security services, logs keystrokes, collects system and user data, and encrypts reports before sending them through hardcoded mail.bg and Hotmail accounts. A dedicated HWP stealer copies itself as HncReporter.exe, changes Hangul document open-handler registry keys, and exfiltrates opened HWP files by email, making the campaign especially relevant to Korean policy and defense targets.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12
EMAIL [email protected] 2013-09-11 2013-09-12

Related Actors

Related Reports

« Back