북 킴수키(Kimsuky) 조직의 정책 자문 위장 스피어 피싱 주의!
2024-03-12 • ESTSecurity • North Kimsuky organization's policy advisory camouflage spear phishing beware! •
ESTsecurity ESRC reports a Kimsuky spear-phishing campaign that impersonated a private policy researcher in South Korea's diplomacy and security community. The email targeted a person at a national defense-related organization with a policy-advisory request and a supposed large HWP attachment download. The lure led to a Naver-themed phishing site at a lookalike domain, where submitted credentials were sent to the attacker before the victim received the real HWP file. Hidden form fields carried a base64-encoded target ID and attachment URL, supporting ESRC's attribution to Kimsuky activity against defense, unification, North Korea, diplomacy, and security targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://nid.naveer.p-e.kr/loadi… | 2024-03-12 | 2024-03-12 |
| DOMAIN | naveer.p-e.kr | 2024-03-12 | 2024-03-12 |
| DOMAIN | nid.naveer.p-e.kr | 2024-03-12 | 2024-03-12 |