탈륨 조직, 2021 코로나19 대응 기부증서 사칭 스피어 피싱 공격 수행

2021-01-24 ESTSecurity Thallium organization conducts spear phishing attack impersonating 2021 COVID-19 response donation certificate

https://blog.alyac.co.kr/3536

Thumbnail for 탈륨 조직, 2021 코로나19 대응 기부증서 사칭 스피어 피싱 공격 수행

ESTsecurity ESRC reported a Thallium spear-phishing campaign timed around Korean year-end tax settlement activity and disguised as a 2021 COVID-19 donation-certificate request. The lure email delivered a ZIP containing a benign-looking PDF and an Excel binary workbook; enabling macros caused the workbook to contact attacker-controlled FTP infrastructure and execute a remote script through regsvr32 and scrobj.dll. The source identifies kvz.factorgpu[.]com and passive DNS address 23.106.160[.]32, linking the activity to a prior Thallium case that used similar malicious-document TTPs and the same last-modifier account. ESRC characterizes Thallium as an active threat actor in Korea using supply-chain attacks, fake servers, and spear phishing across multiple sectors.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2021-01-24 2021-01-24
URL ftp://mufasa:[email protected] 2021-01-24 2021-01-24
URL ftp://mufasa:[email protected] 2021-01-24 2021-01-24
DOMAIN kvz.factorgpu.com 2021-01-24 2021-01-24
IPv4 23.106.160.32 2021-01-24 2021-01-24
DOMAIN search.greenulz.com 2021-01-03 2021-01-24

Related Actors

Related Reports

« Back