탈륨 조직, 2021년 외교부 재외공관 복무 관련 실태 조사 위장 공격

2021-05-07 ESTSecurity Thallium organization camouflaged an investigation into the 2021 Ministry of Foreign Affairs's overseas service service.

https://blog.alyac.co.kr/3754

Thumbnail for 탈륨 조직, 2021년 외교부 재외공관 복무 관련 실태 조사 위장 공격

ESRC attributes a malicious file masquerading as a 2021 Ministry of Foreign Affairs overseas-mission service survey/news document to the North Korea-backed Thallium group. The JSE-based package dropped a decoy PDF plus encoded files under C:\ProgramData\ and installed a 64-bit DLL disguised as ESTsoft update software under C:\ProgramData\Software\ESTsoft\Common\. The DLL registered for autorun, exfiltrated infected-system information to texts.letterpaper.press, and provided remote-control capability. ESRC links the sample to the Blue Estimate campaign because its internal string-encryption method matches prior Thallium tooling.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN re.kr 2021-05-07 2021-05-07

Related Actors

Related Reports

« Back