탈륨(Thallium) 조직, 한국통신사업자연합회 사칭 스피어 피싱 공격 중

2021-09-23 ESTSecurity Thallium organization is carrying out spear phishing attacks impersonating the Korea Telecommunications Operators Association

https://blog.alyac.co.kr/4130

Thumbnail for 탈륨(Thallium) 조직, 한국통신사업자연합회 사칭 스피어 피싱 공격 중

ESTsecurity ESRC attributes a spear-phishing campaign impersonating the Korea Telecommunications Operators Association to Thallium/Kimsuky, a DPRK-linked APT focused on South Korean government and major institutions. The lure email claimed to request a UNMS user-status inspection and delivered a compressed Excel workbook that encouraged victims to enable Office content. Hidden sheets stored obfuscated commands and C2 information that decoded into a regsvr32/scrobj.dll execution chain contacting an attacker-controlled FTP URL at kamika2e[.]com. ESRC notes the document had been seen earlier in the year with only the internal C2 address changed, indicating reuse and continued refinement of Thallium phishing tradecraft.

Related Actors

Related Reports

« Back