북 연계 해킹 조직, 대북 관련 종사자 대상 피싱 공격 진행중!

2023-01-20 ESTSecurity North Korea-linked hacking group conducts phishing attacks against personnel working on North Korea-related issues

https://blog.alyac.co.kr/5052

Thumbnail for 북 연계 해킹 조직, 대북 관련 종사자 대상 피싱 공격 진행중!

ESRC reported a North Korea-linked phishing operation targeting personnel who work on North Korea-related issues. The emails impersonated Kakao security notifications about an overseas login and directed victims to a carefully built phishing page that imitated Kakao login, QR login, and policy menus. Submitted credentials were Base64-encoded and sent to the attacker’s server, and ESRC linked the infrastructure to earlier Smoke Screen activity against diplomacy and security-related targets. The report highlights continued DPRK-aligned credential theft using Korean-language social engineering and Kakao-themed infrastructure such as accountsosi[.]kakaocop[.]eu.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://accountsosi.kakaocop.eu/ 2023-01-20 2023-01-20
DOMAIN accountsosi.kakaocop.eu 2023-01-20 2023-01-20

Related Reports

« Back