특정 논문의 악성 워드 문서를 이용한 APT 공격
2021-10-15 • Ahnlab • APT attack using malicious word documents from specific papers •
ASEC reported targeted malicious Word documents using defense and policy-themed academic lures, including a document based on a real paper about defense reform and military force-structure modernization. The embedded macro matches earlier samples distributed as conference, payment-request, and policy-document lures, suggesting the same operator, and it downloads data from an encoded C2 URL before writing and executing %APPDATA%\desktop.ini through wscript. The source lists related C2 endpoints such as n4028chu.mywebcommunity.org/d.php, 0knw2300.mypressonline[.]com/d.php, and hanjutour.atwebpages[.]com/d.php. ASEC notes related reporting that suspected a Kimsuky/Thallium or other North Korea-linked group, while also allowing for the possibility of imitation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://0knw2300.mypressonline.c… | 2021-10-15 | 2022-08-25 |
| DOMAIN | 0knw2300.mypressonline.com | 2021-10-15 | 2022-08-25 |
| URL | http://hanjutour.atwebpages.com… | 2021-10-15 | 2021-10-15 |
| URL | http://n4028chu.mywebcommunity.… | 2021-10-15 | 2021-10-15 |
| URL | http://n4028chu.atwebpages.com/… | 2021-10-15 | 2021-10-15 |
| URL | http://23000knw.mypressonline.c… | 2021-10-15 | 2021-10-15 |
| DOMAIN | hanjutour.atwebpages.com | 2021-10-15 | 2021-10-15 |
| DOMAIN | 23000knw.mypressonline.com | 2021-10-15 | 2021-10-15 |
| DOMAIN | n4028chu.mywebcommunity.org | 2021-10-15 | 2021-10-15 |
| DOMAIN | n4028chu.atwebpages.com | 2021-10-15 | 2021-10-15 |