북 해킹 조직, 공정거래위원회 사칭 피싱 공격 진행중!

2023-02-02 ESTSecurity North Korean hacking group conducting phishing attacks impersonating the Fair Trade Commission

https://blog.alyac.co.kr/5065

Thumbnail for 북 해킹 조직, 공정거래위원회 사칭 피싱 공격 진행중!

ESRC describes a Konni-attributed phishing campaign impersonating South Korea’s Fair Trade Commission with emails titled as advance notice of a written fact-finding survey. The attached ZIP contained decoy PDF material and LNK files masquerading as HWP documents; executing the shortcuts displayed benign documents while dropping VBS and CAB components into the Public folder. The malware established Run-key persistence, downloaded additional CAB content, executed batch and VBS scripts, and collected process lists, host information, downloads and desktop listings, and public IP data for upload to attacker infrastructure. Reported infrastructure included expressionkey[.]com and naver.down-files[.]com, with hashes for the malicious attachments supplied as IOCs.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://expressionkey.com/list.p… 2023-02-02 2023-11-24
URL http://expressionkey.com/upload… 2023-02-02 2023-11-24
DOMAIN naver.down-files.com 2023-02-02 2023-11-24
DOMAIN expressionkey.com 2023-02-02 2023-11-24
HASH 8e15aadf21efdaa67dd0cae6f0df203d 2023-02-02 2023-02-02
HASH adf8ad0a860ff89a70ca8b94b20c4629 2023-02-02 2023-02-02
HASH 3fcdd49ba79cdfcb062f4784b6224939 2023-02-02 2023-02-02
HASH b12f0a3138b3c8102450814cab077b6f 2023-02-02 2023-02-02
URL https://naver.down-files.com/v2… 2023-02-02 2023-02-02

Related Actors

Related Reports

« Back