북 연계 해킹 조직, 대북 관련 종사자 대상 피싱 공격 진행중!
2023-01-20 • ESTSecurity • North Korea-linked hacking group conducts phishing attacks against personnel working on North Korea-related issues •
ESRC reported a North Korea-linked phishing operation targeting personnel who work on North Korea-related issues. The emails impersonated Kakao security notifications about an overseas login and directed victims to a carefully built phishing page that imitated Kakao login, QR login, and policy menus. Submitted credentials were Base64-encoded and sent to the attacker’s server, and ESRC linked the infrastructure to earlier Smoke Screen activity against diplomacy and security-related targets. The report highlights continued DPRK-aligned credential theft using Korean-language social engineering and Kakao-themed infrastructure such as accountsosi[.]kakaocop[.]eu.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://accountsosi.kakaocop.eu/ | 2023-01-20 | 2023-01-20 |
| DOMAIN | accountsosi.kakaocop.eu | 2023-01-20 | 2023-01-20 |