통일부 북한인권과 토론회로 둔갑한 北 해킹 공격 주의!
2023-02-13 • ESTSecurity • Warning on a North Korean hacking attack disguised as a Ministry of Unification human rights forum •
ESTsecurity reported a North Korea-attributed phishing attack that impersonated a Ministry of Unification human-rights forum co-hosted with a South Korean lawmaker. The lure abused a legitimate encrypted HTML-style notice format used by the ministry, but inserted malicious commands that executed before the user entered the password needed to view the decoy content. ESRC found that a compromised domestic shipping and aviation company website was used as an intermediate host, and that the task-scheduler and mshta/PHP execution pattern matched earlier attacks impersonating the UN Human Rights Office in Seoul and a police identity-theft case. Representative indicators included MD5 hashes DF8B05C389AC9D1B07D2F825EFE6512D and 8CAE06EF26D06863701C78240B2C6535, plus taedusa[.]com PHP paths.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8cae06ef26d06863701c78240b2c6535 | 2023-02-13 | 2023-02-13 |
| HASH | df8b05c389ac9d1b07d2f825efe6512d | 2023-02-13 | 2023-02-13 |
| DOMAIN | taedusa.com | 2023-02-13 | 2023-02-13 |