워드문서 이용한 APT 공격 시도 (External 연결 + VBA 매크로)
2022-02-03 • Ahnlab • APT Attack Attempt Using a Word Document (External Connection + VBA Macro) •
ASEC reported an APT attempt against a broadcasting-company journalist using a malicious Word document disguised as internal financial-work details. Opening the document caused Word to fetch an external DOTM macro from ms-work.com-info.store, which created knla.dat and executed its GetErrorModes export. The DLL contacted the same infrastructure to download and decode an additional in-memory payload, then collected browser account and cookie data from Chrome, Edge, and Firefox into a temporary file before uploading it back to the attacker server. AhnLab detected the document and components as Downloader/XML.Generic, Downloader/DOC.Generic, InfoStealer/Win.Agent, and Trojan/Win.Kimsuky.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://ms-work.com-info.store/d… | 2022-02-03 | 2025-01-14 |
| DOMAIN | ms-work.com-info.store | 2022-02-03 | 2025-01-14 |