‘한국정치외교 학술’ 및 ‘정책자문위원 약력’ 악성 워드문서 유포

2021-07-02 Ahnlab ‘Korean Political Diplomacy Academic' and ‘Policy Advisory Committee Biography' malicious word documents distributed

https://asec.ahnlab.com/ko/24834/

Thumbnail for ‘한국정치외교 학술’ 및 ‘정책자문위원 약력’ 악성 워드문서 유포

AhnLab reports continued distribution of targeted malicious Word documents using Korean political, diplomatic, academic-conference, and policy-advisory biography lures. The DOCX files fetched external DOTM templates such as InterKoreanSummit.dotm and Seminarfinal.dotm, whose obfuscated macros launched PowerShell and downloaded additional scripts from attacker-controlled infrastructure including ripzi.getenjoyment.net and likel.atwebpages.com. The scripts matched earlier malicious Word campaigns with only C2 changes, and document metadata suggested the same creator account seen in previous lure documents. The excerpt does not name a specific DPRK actor, so the summary should treat the activity as North Korea-relevant targeting context rather than assert Kimsuky or Lazarus attribution.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://likel.atwebpages.com/bu/… 2021-07-02 2021-07-15
DOMAIN ripzi.getenjoyment.net 2021-07-02 2021-07-15
DOMAIN likel.atwebpages.com 2021-07-02 2021-07-15
URL http://ripzi.getenjoyment.net/l… 2021-07-02 2021-07-02

Related Reports

« Back