북 관련단체 사칭 악성 전자우편 발송 사건은 북한 소행

2017-01-25 KRNPA North Korea is responsible for sending malicious e-mails impersonating North Korea-related organizations.

https://www.police.go.kr/user/bbs/BD_selectBbs.do?q_bbsCode=1002&q_bbscttSn=1B000001119101000

Attachments

북한발사칭메일수사결과.hwp (468 KB)

South Korean police attributed a malicious email operation against foreign affairs, security, defense, and unification personnel to North Korean infrastructure after tracing activity through overseas relay servers back to an IP range in Ryugyong-dong, Pyongyang. The emails impersonated North Korea-related academic groups and used Hangul attachments such as “Concerned Republic of Korea” and “Analysis of North Korea’s 2017 New Year Address” that could steal information and download and execute additional malware. Investigators connected the activity to a broader 2016 campaign in which 58 impersonation accounts sent malicious or phishing emails to 785 people in government, research, and education organizations, while 69 domestic and overseas relay servers were identified. The case matters for DPRK-focused tracking because it shows sustained credential theft and document-stealing operations using topical North Korea issues, trusted institutional impersonation, and relay infrastructure to target South Korean policy and defense communities.

Related Reports

« Back