위장 탈북 증거로 유인한 '금성121' APT 조직의 '스파이 클라우드' 공격 등장
2020-03-30 • ESTSecurity • A 'Spy Cloud' attack by the 'Geumseong 121' APT organization, lured with fake evidence of defection from North Korea, appears. •
ESRC attributed Operation Spy Cloud to the Geumseong121 APT group after observing spear-phishing emails that lured South Korean targets with fake evidence of North Korean defection. The emails linked to downloadable archives containing a malicious Word document whose obfuscated VBA macro and shellcode contacted Google Drive as C2, retrieved an XOR-encrypted invoice.sca payload, and used pCloud to exfiltrate system information. The report ties the activity to prior Geumseong121 operations through reused cloud accounts, email artifacts such as [email protected], overlapping HWP PostScript techniques, and the same final payload seen in Operation Printing Paper.