북 해킹 조직, 공정거래위원회 사칭 피싱 공격 진행중!
2023-02-02 • ESTSecurity • North Korean hacking group conducting phishing attacks impersonating the Fair Trade Commission •
ESRC describes a Konni-attributed phishing campaign impersonating South Korea’s Fair Trade Commission with emails titled as advance notice of a written fact-finding survey. The attached ZIP contained decoy PDF material and LNK files masquerading as HWP documents; executing the shortcuts displayed benign documents while dropping VBS and CAB components into the Public folder. The malware established Run-key persistence, downloaded additional CAB content, executed batch and VBS scripts, and collected process lists, host information, downloads and desktop listings, and public IP data for upload to attacker infrastructure. Reported infrastructure included expressionkey[.]com and naver.down-files[.]com, with hashes for the malicious attachments supplied as IOCs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://expressionkey.com/list.p… | 2023-02-02 | 2023-11-24 |
| URL | http://expressionkey.com/upload… | 2023-02-02 | 2023-11-24 |
| DOMAIN | naver.down-files.com | 2023-02-02 | 2023-11-24 |
| DOMAIN | expressionkey.com | 2023-02-02 | 2023-11-24 |
| HASH | 8e15aadf21efdaa67dd0cae6f0df203d | 2023-02-02 | 2023-02-02 |
| HASH | adf8ad0a860ff89a70ca8b94b20c4629 | 2023-02-02 | 2023-02-02 |
| HASH | 3fcdd49ba79cdfcb062f4784b6224939 | 2023-02-02 | 2023-02-02 |
| HASH | b12f0a3138b3c8102450814cab077b6f | 2023-02-02 | 2023-02-02 |
| URL | https://naver.down-files.com/v2… | 2023-02-02 | 2023-02-02 |