탈륨 조직, 사설 주식 투자 메신저 악용해 소프트웨어 공급망 공격 수행
2021-01-03 • ESTSecurity • Thallium organization exploits private stock investment messenger to carry out software supply chain attacks •
ESRC reported that the North Korea-linked Thallium group modified a private stock-investment messenger installer to conduct a software supply-chain attack, expanding beyond its usual spear-phishing activity. The NSIS installer executed wmic.exe to retrieve remote XSL/VBS commands over FTP, created ProgramData folders such as OracleCache, PackageUninstall, and USODrive, and contacted frog.smtper[.]co for follow-on commands. Persistence was established through a scheduled task named Office365__ that repeatedly ran usopub.vbs and used WMIC to beacon to the attacker-controlled FTP path with victim PC information. ESRC also observed malicious documents using the same XSL Script Processing technique and noted search.greenulz[.]com as related infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | search.greenulz.com | 2021-01-03 | 2021-01-24 |
| DOMAIN | frog.smtper.co | 2021-01-03 | 2021-01-03 |