(주의) 외교부로 위장한 악성 한글 문서 주의!!

2019-03-13 Hauri (Caution) Beware of malicious Korean documents disguised as the Ministry of Foreign Affairs!!

https://www.hauri.co.kr/security/issue_view.html?intSeq=392&page=1

Thumbnail for (주의) 외교부로 위장한 악성 한글 문서 주의!!

Hauri reports continued abuse of malicious Hangul documents delivered by email to Korean users, with one case impersonating a Ministry of Foreign Affairs employee to increase trust. The infection chain uses a link to a malicious HWP document, embedded script execution, and follow-on script downloads from attacker-controlled web paths. The listed infrastructure includes multiple defanged HTTP URLs used for script retrieval, registration with MAC-address parameters, and additional download or query endpoints. The targeting appears focused rather than mass-distributed, aimed at recipients handling diplomacy-related work, creating risk of information theft or further malicious activity on compromised systems.

« Back