탈륨 조직, 사설 주식 투자 메신저 악용해 소프트웨어 공급망 공격 수행

2021-01-03 ESTSecurity Thallium organization exploits private stock investment messenger to carry out software supply chain attacks

https://blog.alyac.co.kr/3489

Thumbnail for 탈륨 조직, 사설 주식 투자 메신저 악용해 소프트웨어 공급망 공격 수행

ESRC reported that the North Korea-linked Thallium group modified a private stock-investment messenger installer to conduct a software supply-chain attack, expanding beyond its usual spear-phishing activity. The NSIS installer executed wmic.exe to retrieve remote XSL/VBS commands over FTP, created ProgramData folders such as OracleCache, PackageUninstall, and USODrive, and contacted frog.smtper[.]co for follow-on commands. Persistence was established through a scheduled task named Office365__ that repeatedly ran usopub.vbs and used WMIC to beacon to the attacker-controlled FTP path with victim PC information. ESRC also observed malicious documents using the same XSL Script Processing technique and noted search.greenulz[.]com as related infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN search.greenulz.com 2021-01-03 2021-01-24
DOMAIN frog.smtper.co 2021-01-03 2021-01-03

Related Actors

Related Reports

« Back