포세이돈 작전: 구글 광고 리다이렉션 메커니즘을 악용한 스피어 피싱 공격
2026-01-18 • Genians • Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms •
https://www.genians.co.kr/blog/threat_intelligence/spear-phishing
Genians attributes Operation Poseidon to the Konni APT and describes spear-phishing activity that impersonated South Korean financial institutions and North Korean human rights organizations. The campaign used Google Ads and earlier NAVER ad-click redirection URLs to make malicious download links appear like legitimate advertising traffic before sending victims to compromised WordPress infrastructure. The delivery chain relied on ZIP archives containing LNK files, followed by AutoIt scripts masquerading as PDF execution and loading EndRAT-family remote access malware. Evidence includes reused C2 infrastructure such as jlrandsons.co[.]uk and internal build-path strings referencing "Poseidon - Attack" and client versioning. The report highlights how Konni blended business-themed lures, redirect abuse, tracking beacons, and content-padding evasion to bypass both user suspicion and security filtering.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 109.234.36.135 | 2025-11-09 | 2026-01-22 |
| HASH | 0777781dedd57f8016b7c627411bdf2c | 2026-01-18 | 2026-01-18 |
| HASH | 639b5489d2fb79bcb715905a046d4a54 | 2026-01-18 | 2026-01-18 |
| HASH | 94935397dce29684f384e57f85beeb0a | 2026-01-18 | 2026-01-18 |
| HASH | d6aa7e9ff0528425146e64d9472ffdbd | 2026-01-18 | 2026-01-18 |
| HASH | 908d074f69c0bf203ed225557b7827ec | 2026-01-18 | 2026-01-18 |
| HASH | a9a52e2f2afe28778a8537f955ee1310 | 2026-01-18 | 2026-01-18 |
| HASH | a58ef1e53920a6e528dc31001f302c7b | 2026-01-18 | 2026-01-18 |
| HASH | d4b06cb4ed834c295d0848b90a109f09 | 2026-01-18 | 2026-01-18 |
| HASH | 303c5e4842613f7b9ee408e5c6721c00 | 2026-01-18 | 2026-01-18 |
| HASH | f5842320e04c2c97d1f69cebfd47df3d | 2026-01-18 | 2026-01-18 |
| HASH | 0171338d904381bbf3d1a909a48f4e92 | 2026-01-18 | 2026-01-18 |
| HASH | ad6273981cb53917cb8bda8e2f2e31a8 | 2026-01-18 | 2026-01-18 |
| DOMAIN | tatukikai.jp | 2026-01-18 | 2026-01-18 |
| DOMAIN | anupamaivf.com | 2026-01-18 | 2026-01-18 |
| DOMAIN | encryptuganda.org | 2026-01-18 | 2026-01-18 |
| DOMAIN | vintashmarket.com | 2026-01-18 | 2026-01-18 |
| DOMAIN | aceeyl.com | 2026-01-18 | 2026-01-18 |
| DOMAIN | kyowaind.co.jp | 2026-01-18 | 2026-01-18 |
| DOMAIN | creativepackout.co | 2026-01-18 | 2026-01-18 |
| DOMAIN | jlrandsons.co.uk | 2026-01-18 | 2026-01-18 |
| DOMAIN | igamingroundtable.com | 2026-01-18 | 2026-01-18 |
| DOMAIN | ad.doubleclick.net | 2026-01-18 | 2026-01-18 |
| DOMAIN | althouqroastery.com | 2026-01-18 | 2026-01-18 |
| DOMAIN | pomozzi.com | 2026-01-18 | 2026-01-18 |
| IPv4 | 144.124.247.97 | 2026-01-18 | 2026-01-18 |
| DOMAIN | genuinashop.com | 2025-11-09 | 2026-01-18 |
| IPv4 | 77.246.101.72 | 2025-11-09 | 2026-01-18 |
| IPv4 | 77.246.108.96 | 2025-11-09 | 2026-01-18 |
| HASH | 8b8fa6c4298d83d78e11b52f22a79100 | 2025-08-08 | 2026-01-18 |
| HASH | 6a4c3256ff063f67d3251d6dd8229931 | 2025-05-26 | 2026-01-18 |
| DOMAIN | nationalinterestparty.com | 2025-04-01 | 2026-01-18 |