북 킴수키(Kimsuky) 조직의 정책 자문 위장 스피어 피싱 주의!

2024-03-12 ESTSecurity North Kimsuky organization's policy advisory camouflage spear phishing beware!

https://alyacofficialblog.tistory.com/5354

ESTsecurity ESRC reports a Kimsuky spear-phishing campaign that impersonated a private policy researcher in South Korea's diplomacy and security community. The email targeted a person at a national defense-related organization with a policy-advisory request and a supposed large HWP attachment download. The lure led to a Naver-themed phishing site at a lookalike domain, where submitted credentials were sent to the attacker before the victim received the real HWP file. Hidden form fields carried a base64-encoded target ID and attachment URL, supporting ESRC's attribution to Kimsuky activity against defense, unification, North Korea, diplomacy, and security targets.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://nid.naveer.p-e.kr/loadi… 2024-03-12 2024-03-12
DOMAIN naveer.p-e.kr 2024-03-12 2024-03-12
DOMAIN nid.naveer.p-e.kr 2024-03-12 2024-03-12

Related Actors

Related Reports

« Back