안보·외교·통일 관련 분야를 겨냥한 APT 공격, '작전명 블랙 리무진' 주의

2018-11-27 ESTSecurity APT attacks targeting areas related to security, diplomacy, and unification, beware of ‘Operation Black Limousine'

http://blog.alyac.co.kr/2004

Thumbnail for 안보·외교·통일 관련 분야를 겨냥한 APT 공격, '작전명 블랙 리무진' 주의

ESRC links Operation Black Limousine to ongoing Kimsuky activity targeting South Korean political, social, security, diplomacy, and unification-related interests. The analyzed lure used a malicious HWP document themed around a personal-information consent form and national R&D regulations, with an embedded BIN0001.eps PostScript component carrying encrypted shellcode. After decryption, the shellcode attempted to contact rentcartoday.com as command-and-control infrastructure and could download and execute an additional payload. The report warns that successful infection may enable data theft and remote control, while updating Hancom Office removes the vulnerable Ghostscript engine used by this EPS attack path.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN rentcartoday.com 2018-11-27 2018-11-27

Related Actors

Related Reports

« Back