북한 정찰총국 해킹 조직, 한국 싱크탱크 사칭으로 국방,안보전문가 표적 공격!

2021-11-09 ESTSecurity North Korea's Reconnaissance General Bureau hacking organization targets national defense and security experts by impersonating a South Korean think tank!

https://blog.alyac.co.kr/4255

Thumbnail for 북한 정찰총국 해킹 조직, 한국 싱크탱크 사칭으로 국방,안보전문가 표적 공격!

ESRC describes a spear-phishing campaign impersonating a South Korean think-tank workshop to target defense and national-security experts with a malicious DOCX file. The lure exploited MSHTML remote-code-execution vulnerability CVE-2021-40444, allowing an ActiveX control to install additional malware when opened on an unpatched Microsoft Office system. ESRC assesses the activity as an extension of the Fake Striker APT campaign and links it to a hacking organization associated with North Korea’s Reconnaissance General Bureau. The report highlights the attackers’ rapid operational use of CVE-2021-40444 after public disclosure and notes earlier use of CVE-2020-9715 in related document attacks.

Related Reports

« Back