킴수키(Kimsuky), '사이버 안전국' 메일을 위장한 해킹 시도!
2023-03-14 • ESTSecurity • Kimsuky hacking attempt disguised as a Cyber Safety Bureau email •
ESRC attributes a Korean phishing campaign to Kimsuky, targeting people connected to North Korea-related organizations with email impersonating the Cyber Safety Bureau. The lure claimed the recipient faced legal or account-abuse issues and attached an archive containing a CHM file named for information-network law; running it displayed benign help content while executing a background Click() script. The script stored encoded commands in Document.dat, used Certutil to decode them into Document.vbs, registered persistence through the Run key, and executed PowerShell from ibsq.co.kr to steal user information. The report notes North Korean wording in the email body and lists hashes plus ibsq.co.kr URLs as representative indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ibsq.co.kr | 2023-03-14 | 2023-06-09 |
| HASH | ded83a6bd7438b34b058f2fe5ee54c7e | 2023-03-14 | 2023-05-24 |
| URL | http://ibsq.co.kr/config/demo.t… | 2023-03-14 | 2023-05-24 |
| HASH | 0f1a2d2104269be9afadaab2b644fbb6 | 2023-03-14 | 2023-03-14 |
| HASH | 7ba620bf5151e68890d818629587cb14 | 2023-03-14 | 2023-03-14 |
| URL | http://ibsq.co.kr/config/show.p… | 2023-03-14 | 2023-03-14 |