북한 해킹 단체 김수키(Kimsuky) 한국방위산업학회 향한 악성코드 공격-한국방위산업학회 방위산업 디지털 혁신 세미나(계획)(2025.1.12)
2025-01-15 • Sakai • Malware Attack by the North Korean Hacking Group Kimsuky Targeting the Korea Defense Industry Association - Korea Defense Industry Association Defense Industry Digital Innovation Seminar Plan (2025.1.12) •
The Korean-language source attributes a malicious HWP lure targeting the Korea Association of Defense Industry Studies to Kimsuky. The attack begins with an email about a defense-industry digital innovation seminar and includes an HWP attachment that waits at a password prompt before executing malicious behavior. After execution, the document chain renames and opens a decoy PDF, copies files through the temporary directory, writes executables and manifests under AppData, and creates scheduled tasks named TemporaryStatescleanesdfrs and TemporaryStatescleansders_1 for persistence. The excerpt provides hashes for the HWP sample and notes detections such as Trojan/HWP.Agent and Exploit.HWP.Agent, making it relevant to defenders monitoring DPRK targeting of South Korean defense-sector organizations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 63a119714f01d9ff57c51614c9727f84 | 2025-01-15 | 2026-01-14 |
| DOMAIN | hvil-telegram.org | 2025-01-15 | 2025-01-24 |
| HASH | d7367d9cc84d794ff73e90dd3cc936b… | 2025-01-15 | 2025-01-15 |
| HASH | aa59e1d70ce58c5882b5890d86e63a3… | 2025-01-15 | 2025-01-15 |