북 해킹 조직, 국내 유명 모바일 메신저를 통해 공격 진행 중!

2022-08-22 ESTSecurity North Korean hacking organization is conducting attacks through famous domestic mobile messengers!

https://blog.alyac.co.kr/4882

Thumbnail for 북 해킹 조직, 국내 유명 모바일 메신저를 통해 공격 진행 중!

ESRC reports a North Korea-linked hacking operation targeting PC users of KakaoTalk by impersonating KakaoPay with a lookalike account name. The attacker lowers suspicion with periodic event and service messages before sending a ZIP archive disguised as a revised privacy policy. The archive contains an executable masquerading with a .pif extension; when run, it opens a benign PDF while malware executes in the background. ESRC attributes the activity to Geumseong 121, linked to North Korea's Reconnaissance General Bureau, and says the malware steals user information, sends it to an attacker server, and waits for further commands.

Related Actors

Related Reports

« Back