킴수키(Kimsuky), '사이버 안전국' 메일을 위장한 해킹 시도!

2023-03-14 ESTSecurity Kimsuky hacking attempt disguised as a Cyber Safety Bureau email

https://blog.alyac.co.kr/5102

Thumbnail for 킴수키(Kimsuky), '사이버 안전국' 메일을 위장한 해킹 시도!

ESRC attributes a Korean phishing campaign to Kimsuky, targeting people connected to North Korea-related organizations with email impersonating the Cyber Safety Bureau. The lure claimed the recipient faced legal or account-abuse issues and attached an archive containing a CHM file named for information-network law; running it displayed benign help content while executing a background Click() script. The script stored encoded commands in Document.dat, used Certutil to decode them into Document.vbs, registered persistence through the Run key, and executed PowerShell from ibsq.co.kr to steal user information. The report notes North Korean wording in the email body and lists hashes plus ibsq.co.kr URLs as representative indicators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ibsq.co.kr 2023-03-14 2023-06-09
HASH ded83a6bd7438b34b058f2fe5ee54c7e 2023-03-14 2023-05-24
URL http://ibsq.co.kr/config/demo.t… 2023-03-14 2023-05-24
HASH 0f1a2d2104269be9afadaab2b644fbb6 2023-03-14 2023-03-14
HASH 7ba620bf5151e68890d818629587cb14 2023-03-14 2023-03-14
URL http://ibsq.co.kr/config/show.p… 2023-03-14 2023-03-14

Related Actors

Related Reports

« Back