특정 논문의 악성 워드 문서를 이용한 APT 공격

2021-10-15 Ahnlab APT attack using malicious word documents from specific papers

https://asec.ahnlab.com/ko/27760/

Thumbnail for 특정 논문의 악성 워드 문서를 이용한 APT 공격

ASEC reported targeted malicious Word documents using defense and policy-themed academic lures, including a document based on a real paper about defense reform and military force-structure modernization. The embedded macro matches earlier samples distributed as conference, payment-request, and policy-document lures, suggesting the same operator, and it downloads data from an encoded C2 URL before writing and executing %APPDATA%\desktop.ini through wscript. The source lists related C2 endpoints such as n4028chu.mywebcommunity.org/d.php, 0knw2300.mypressonline[.]com/d.php, and hanjutour.atwebpages[.]com/d.php. ASEC notes related reporting that suspected a Kimsuky/Thallium or other North Korea-linked group, while also allowing for the possibility of imitation.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://0knw2300.mypressonline.c… 2021-10-15 2022-08-25
DOMAIN 0knw2300.mypressonline.com 2021-10-15 2022-08-25
URL http://hanjutour.atwebpages.com… 2021-10-15 2021-10-15
URL http://n4028chu.mywebcommunity.… 2021-10-15 2021-10-15
URL http://n4028chu.atwebpages.com/… 2021-10-15 2021-10-15
URL http://23000knw.mypressonline.c… 2021-10-15 2021-10-15
DOMAIN hanjutour.atwebpages.com 2021-10-15 2021-10-15
DOMAIN 23000knw.mypressonline.com 2021-10-15 2021-10-15
DOMAIN n4028chu.mywebcommunity.org 2021-10-15 2021-10-15
DOMAIN n4028chu.atwebpages.com 2021-10-15 2021-10-15

Related Actors

Related Reports

« Back