워드문서 이용한 APT 공격 시도 (External 연결 + VBA 매크로)

2022-02-03 Ahnlab APT Attack Attempt Using a Word Document (External Connection + VBA Macro)

https://asec.ahnlab.com/ko/30980/

Thumbnail for 워드문서 이용한 APT 공격 시도 (External 연결 + VBA 매크로)

ASEC reported an APT attempt against a broadcasting-company journalist using a malicious Word document disguised as internal financial-work details. Opening the document caused Word to fetch an external DOTM macro from ms-work.com-info.store, which created knla.dat and executed its GetErrorModes export. The DLL contacted the same infrastructure to download and decode an additional in-memory payload, then collected browser account and cookie data from Chrome, Edge, and Firefox into a temporary file before uploading it back to the attacker server. AhnLab detected the document and components as Downloader/XML.Generic, Downloader/DOC.Generic, InfoStealer/Win.Agent, and Trojan/Win.Kimsuky.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://ms-work.com-info.store/d… 2022-02-03 2025-01-14
DOMAIN ms-work.com-info.store 2022-02-03 2025-01-14

Related Actors

Related Reports

« Back