포세이돈 작전: 구글 광고 리다이렉션 메커니즘을 악용한 스피어 피싱 공격

2026-01-18 Genians Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms

https://www.genians.co.kr/blog/threat_intelligence/spear-phishing

Thumbnail for 포세이돈 작전: 구글 광고 리다이렉션 메커니즘을 악용한 스피어 피싱 공격

Genians attributes Operation Poseidon to the Konni APT and describes spear-phishing activity that impersonated South Korean financial institutions and North Korean human rights organizations. The campaign used Google Ads and earlier NAVER ad-click redirection URLs to make malicious download links appear like legitimate advertising traffic before sending victims to compromised WordPress infrastructure. The delivery chain relied on ZIP archives containing LNK files, followed by AutoIt scripts masquerading as PDF execution and loading EndRAT-family remote access malware. Evidence includes reused C2 infrastructure such as jlrandsons.co[.]uk and internal build-path strings referencing "Poseidon - Attack" and client versioning. The report highlights how Konni blended business-themed lures, redirect abuse, tracking beacons, and content-padding evasion to bypass both user suspicion and security filtering.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 109.234.36.135 2025-11-09 2026-01-22
HASH 0777781dedd57f8016b7c627411bdf2c 2026-01-18 2026-01-18
HASH 639b5489d2fb79bcb715905a046d4a54 2026-01-18 2026-01-18
HASH 94935397dce29684f384e57f85beeb0a 2026-01-18 2026-01-18
HASH d6aa7e9ff0528425146e64d9472ffdbd 2026-01-18 2026-01-18
HASH 908d074f69c0bf203ed225557b7827ec 2026-01-18 2026-01-18
HASH a9a52e2f2afe28778a8537f955ee1310 2026-01-18 2026-01-18
HASH a58ef1e53920a6e528dc31001f302c7b 2026-01-18 2026-01-18
HASH d4b06cb4ed834c295d0848b90a109f09 2026-01-18 2026-01-18
HASH 303c5e4842613f7b9ee408e5c6721c00 2026-01-18 2026-01-18
HASH f5842320e04c2c97d1f69cebfd47df3d 2026-01-18 2026-01-18
HASH 0171338d904381bbf3d1a909a48f4e92 2026-01-18 2026-01-18
HASH ad6273981cb53917cb8bda8e2f2e31a8 2026-01-18 2026-01-18
DOMAIN tatukikai.jp 2026-01-18 2026-01-18
DOMAIN anupamaivf.com 2026-01-18 2026-01-18
DOMAIN encryptuganda.org 2026-01-18 2026-01-18
DOMAIN vintashmarket.com 2026-01-18 2026-01-18
DOMAIN aceeyl.com 2026-01-18 2026-01-18
DOMAIN kyowaind.co.jp 2026-01-18 2026-01-18
DOMAIN creativepackout.co 2026-01-18 2026-01-18
DOMAIN jlrandsons.co.uk 2026-01-18 2026-01-18
DOMAIN igamingroundtable.com 2026-01-18 2026-01-18
DOMAIN ad.doubleclick.net 2026-01-18 2026-01-18
DOMAIN althouqroastery.com 2026-01-18 2026-01-18
DOMAIN pomozzi.com 2026-01-18 2026-01-18
IPv4 144.124.247.97 2026-01-18 2026-01-18
DOMAIN genuinashop.com 2025-11-09 2026-01-18
IPv4 77.246.101.72 2025-11-09 2026-01-18
IPv4 77.246.108.96 2025-11-09 2026-01-18
HASH 8b8fa6c4298d83d78e11b52f22a79100 2025-08-08 2026-01-18
HASH 6a4c3256ff063f67d3251d6dd8229931 2025-05-26 2026-01-18
DOMAIN nationalinterestparty.com 2025-04-01 2026-01-18

Related Actors

Related Reports

« Back