탈륨 APT 위협 행위자들의 흔적과 악성파일 사례별 비교 분석
2020-10-13 • ESTSecurity • Comparative analysis of traces of thallium APT threat actors and malicious files by case •
ESRC reports continued Thallium APT activity against South Korea-focused North Korea human-rights and defector-related targets. Recent malicious Word documents were created by the same account name, used a shared macro-lure image hash, and executed obfuscated PowerShell that contacted attacker-controlled web hosts such as atwebpages/myartsonline infrastructure to retrieve additional commands. The activity relied on Korean-language spear-phishing lures impersonating government or research contexts and showed recurring operator traces including Korean keyboard/font artifacts and the WebKitFormBoundarywhpFxMBe19cSjFnG string associated with earlier Thallium tooling. The report highlights a shift toward malicious DOC macro delivery and keylogger follow-on payloads rather than HWP exploit-heavy tradecraft.