킴수키 해킹조직의 구글 브라우저 및 앱 스토어 서비스 악용 공격 주의
2023-03-20 • KRNCSC • Beware of attacks by Kimsuki hacking organization that exploit Google browser and app store services •
Attachments
South Korea’s NIS and Germany’s BfV warned that Kimsuky, also known as Thallium or Velvet Chollima, abused Google browser and app-store services to target Korean Peninsula and North Korea specialists. The advisory describes spear-phishing that led victims to install a malicious Chromium extension, which activated during Gmail sessions and used DevTools API functionality to steal email while bypassing some user security settings. It also describes attackers using previously stolen Google credentials and Google Play’s web-to-phone synchronization workflow to push internally tested malicious Android apps to linked smartphones without victim interaction. The source lists infrastructure and artifacts including siekis[.]com, navernnail[.]com, lowerp.onlinewebshop[.]net, 23.106.122[.]16, the %APPDATA%\AF folder, and FastSpy/Kimsuky Android samples.