통일부 북한인권과 토론회로 둔갑한 北 해킹 공격 주의!

2023-02-13 ESTSecurity Warning on a North Korean hacking attack disguised as a Ministry of Unification human rights forum

https://blog.alyac.co.kr/5071

Thumbnail for 통일부 북한인권과 토론회로 둔갑한 北 해킹 공격 주의!

ESTsecurity reported a North Korea-attributed phishing attack that impersonated a Ministry of Unification human-rights forum co-hosted with a South Korean lawmaker. The lure abused a legitimate encrypted HTML-style notice format used by the ministry, but inserted malicious commands that executed before the user entered the password needed to view the decoy content. ESRC found that a compromised domestic shipping and aviation company website was used as an intermediate host, and that the task-scheduler and mshta/PHP execution pattern matched earlier attacks impersonating the UN Human Rights Office in Seoul and a police identity-theft case. Representative indicators included MD5 hashes DF8B05C389AC9D1B07D2F825EFE6512D and 8CAE06EF26D06863701C78240B2C6535, plus taedusa[.]com PHP paths.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8cae06ef26d06863701c78240b2c6535 2023-02-13 2023-02-13
HASH df8b05c389ac9d1b07d2f825efe6512d 2023-02-13 2023-02-13
DOMAIN taedusa.com 2023-02-13 2023-02-13

Related Reports

« Back