탈륨 조직, 코로나19 관련 소상공인 지원 종합안내로 위장한 HWP 공격

2021-02-17 ESTSecurity Thallium organization attacks HWP disguised as a comprehensive guide to support small business owners related to COVID-19

https://blog.alyac.co.kr/3586

Thumbnail for 탈륨 조직, 코로나19 관련 소상공인 지원 종합안내로 위장한 HWP 공격

ESTsecurity analyzed a Thallium-attributed malicious HWP document disguised as a COVID-19 small-business support guide. The document used embedded OLE objects and fake confirmation imagery to lure the user into launching apisecurity.vbs, which staged apisecurity.key as xmllite.dll under the OneDrive directory for DLL side-loading by OneDrive.exe. The payload attempted command-and-control communication through an FTP-formatted WMIC/XSL Script Processing command referencing b.smtper[.]co, and the article linked the tradecraft to earlier Thallium spear-phishing and supply-chain cases. The report highlights continued use of Korean-language document lures, HWP/OLE execution tricks, and stealthy OneDrive-based side-loading by this North Korea-linked cluster.

Indicators of Compromise

Type Value First Seen Last Seen
URL ftp://u:[email protected]/beta/usop… 2021-02-17 2021-02-17
DOMAIN b.smtper.co 2021-02-17 2021-02-17

Related Actors

Related Reports

« Back