오퍼레이션 김수키(Kimsuky)의 은밀한 활동, 한국 맞춤형 APT 공격은 현재 진행형

2018-02-12 ESTSecurity Operation Kimsuky's covert activities and Korean-tailored APT attacks are currently in progress.

http://blog.alyac.co.kr/1536

Thumbnail for 오퍼레이션 김수키(Kimsuky)의 은밀한 활동, 한국 맞춤형 APT 공격은 현재 진행형

ESRC reported that Kimsuky-linked activity against South Korean targets was still active in 2018 and had evolved from earlier public reporting. The attacks primarily used spear-phishing with malicious HWP documents themed around North Korea and inter-Korean social or cultural cooperation, with repeated metadata such as the author value “mofa” and matching shellcode across samples. The shellcode checked the string “JOYBERTM,” decoded an embedded payload, and used process hollowing to run malicious code inside userinit.exe before contacting attacker-controlled hosting such as maii-daum-net.atwebpages.com. The report also tied related variants to earlier Korean targets through shared HTTP multipart parameters, C2 domains that imitated Korean services, and the GHOST419 keyword used to retrieve XOR-encrypted follow-on malware.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN maii-daum-net.atwebpages.com 2018-02-12 2018-02-12
DOMAIN nate-on.bugs3.com 2018-02-12 2018-02-12
DOMAIN ink.inkboom.co.kr 2018-02-02 2018-02-12
DOMAIN followgho.byethost7.com 2018-02-02 2018-02-12

Related Actors

Related Reports

« Back