외교안보 전문가 대상 표적 공격 급증 주의보 ‘탈륨’ 조직 연루

2021-03-10 ESTSecurity Warning of rapid increase in targeted attacks targeting diplomatic and security experts, ‘Thallium' organization implicated

https://blog.alyac.co.kr/3624

Thumbnail for 외교안보 전문가 대상 표적 공격 급증 주의보 ‘탈륨’ 조직 연루

ESTsecurity warned of a surge in Thallium-linked spear-phishing against South Korean diplomacy, security, unification and defense-policy experts. The attackers impersonated media outlets, policy institutes, academic societies and North Korea-policy forums, sending tailored emails that requested papers, seminar participation forms, honorarium documents or personal-information consent forms to lure victims into opening malicious attachments. The report notes a shift toward DOC-based attacks with fake English enable-content screens and malicious macros or remote template execution, including apparent imitation of TA551-style document templates. Observed C2 infrastructure included yezu212.myartsonline.com and quarez.atwebpages.com, and ALYac detected the malware as Trojan.Downloader.DOC.Gen.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN quarez.atwebpages.com 2021-03-10 2021-11-01
DOMAIN yezu212.myartsonline.com 2021-03-10 2021-03-10

Related Actors

Related Reports

« Back