외교안보 전문가 대상 표적 공격 급증 주의보 ‘탈륨’ 조직 연루
2021-03-10 • ESTSecurity • Warning of rapid increase in targeted attacks targeting diplomatic and security experts, ‘Thallium' organization implicated •
ESTsecurity warned of a surge in Thallium-linked spear-phishing against South Korean diplomacy, security, unification and defense-policy experts. The attackers impersonated media outlets, policy institutes, academic societies and North Korea-policy forums, sending tailored emails that requested papers, seminar participation forms, honorarium documents or personal-information consent forms to lure victims into opening malicious attachments. The report notes a shift toward DOC-based attacks with fake English enable-content screens and malicious macros or remote template execution, including apparent imitation of TA551-style document templates. Observed C2 infrastructure included yezu212.myartsonline.com and quarez.atwebpages.com, and ALYac detected the malware as Trojan.Downloader.DOC.Gen.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | quarez.atwebpages.com | 2021-03-10 | 2021-11-01 |
| DOMAIN | yezu212.myartsonline.com | 2021-03-10 | 2021-03-10 |