외화벌이를 목적으로 하는 北 배후의 써미츠 NFT 보상 사칭 해킹 주의!

2022-07-25 ESTSecurity Warning about a North Korea-linked hacking campaign impersonating Summitz NFT rewards for foreign currency earning

https://blog.alyac.co.kr/4854

Thumbnail for 외화벌이를 목적으로 하는 北 배후의 써미츠 NFT 보상 사칭 해킹 주의!

ESRC reported a North Korea-linked phishing campaign impersonating Summitz coin victim NFT compensation notices to target prior investors, NFT-curious recipients, and Bitcoin holders. The email directed victims to an attached “NFT compensation plan” lure and then to private-banking-group[.]com, where account details entered for identity verification were sent to the attacker. The investigation also connected sslnaver[.]online, cdndaum[.]online, lion.simba21@protonmail[.]com, and repeated portal helpdesk impersonation infrastructure used against defectors and diplomacy, security, and unification-related targets. ESRC tied the activity to the North Korea-linked KGH campaign and noted overlap with earlier attacks impersonating a broadcaster, the Japan Institute of International Affairs, and health certificate issuance themes.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2022-07-25 2022-07-25
EMAIL [email protected] 2022-07-25 2022-07-25
DOMAIN private-banking-group.com 2022-07-25 2022-07-25

Related Reports

« Back