북한 최근 정세 칼럼으로 위장한 北 연계 '금성121' APT 공격 주의!
2021-09-07 • ESTSecurity • Beware of North Korea-linked ‘Geumseong 121' APT attack disguised as a column on North Korea's recent political situation! •
ESRC reported a North Korea-linked Geumseong121 campaign that used spear-phishing against a North Korean human-rights organization leader with a malicious DOC disguised as a column about recent North Korean political and security issues. The attacker allegedly compromised or abused an SNS relationship to build trust, then delivered the macro-enabled document by email; enabling macros exposed the victim to compromise. ESRC connected the malware to prior “Spy Cloud” activity through similar macro routines and artifacts such as Weapon and bluelight PDB paths, and noted the group’s broader use of cloud services, watering-hole attacks, and Android smishing to steal personal and device data.