탈륨 조직, 코로나19 관련 소상공인 지원 종합안내로 위장한 HWP 공격
2021-02-17 • ESTSecurity • Thallium organization attacks HWP disguised as a comprehensive guide to support small business owners related to COVID-19 •
ESTsecurity analyzed a Thallium-attributed malicious HWP document disguised as a COVID-19 small-business support guide. The document used embedded OLE objects and fake confirmation imagery to lure the user into launching apisecurity.vbs, which staged apisecurity.key as xmllite.dll under the OneDrive directory for DLL side-loading by OneDrive.exe. The payload attempted command-and-control communication through an FTP-formatted WMIC/XSL Script Processing command referencing b.smtper[.]co, and the article linked the tradecraft to earlier Thallium spear-phishing and supply-chain cases. The report highlights continued use of Korean-language document lures, HWP/OLE execution tricks, and stealthy OneDrive-based side-loading by this North Korea-linked cluster.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | ftp://u:[email protected]/beta/usop… | 2021-02-17 | 2021-02-17 |
| DOMAIN | b.smtper.co | 2021-02-17 | 2021-02-17 |