울진 산불 피해 기부 영수증으로 위장한 워드 문서 APT 공격 (Kimsuky)

2022-03-30 Ahnlab Word document APT attack disguised as donation receipt for Uljin forest fire damage (Kimsuky)

https://asec.ahnlab.com/ko/33224/

Thumbnail for 울진 산불 피해 기부 영수증으로 위장한 워드 문서 APT 공격 (Kimsuky)

AhnLab ASEC attributed a malicious Word-document APT lure disguised as an Uljin forest-fire donation receipt to Kimsuky. The document was created on March 28 by an author name previously seen in ASEC reporting and reused earlier Kimsuky tradecraft while changing the generated batch filename to moster.bat. When macros run, moster.bat registers start.vbs in the Run key, launches no4.bat, and reaches hxxp://nomonth-man[.]com/dfg04/%COMPUTERNAME%.txt to download additional content. ASEC assessed the actor as broadening targets beyond North Korea-related and cryptocurrency personnel, making the social-issue lure notable for Korean users handling unsolicited Word files.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://nomonth-man.com/dfg04/%C… 2022-03-30 2022-03-30
DOMAIN nomonth-man.com 2022-03-30 2022-03-30

Related Actors

Related Reports

« Back