탈륨 조직, 2021년 외교부 재외공관 복무 관련 실태 조사 위장 공격
2021-05-07 • ESTSecurity • Thallium organization camouflaged an investigation into the 2021 Ministry of Foreign Affairs's overseas service service. •
ESRC attributes a malicious file masquerading as a 2021 Ministry of Foreign Affairs overseas-mission service survey/news document to the North Korea-backed Thallium group. The JSE-based package dropped a decoy PDF plus encoded files under C:\ProgramData\ and installed a 64-bit DLL disguised as ESTsoft update software under C:\ProgramData\Software\ESTsoft\Common\. The DLL registered for autorun, exfiltrated infected-system information to texts.letterpaper.press, and provided remote-control capability. ESRC links the sample to the Blue Estimate campaign because its internal string-encryption method matches prior Thallium tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | re.kr | 2021-05-07 | 2021-05-07 |