한미(독) 합동 보안권고문으로 보는 북의 해킹 활동
2024-01-29 • KRNCSC • North Korea's hacking activities seen in the ROK-US (Germany) joint security advisory •
NCSC's discussion of South Korea, U.S., and Germany joint advisories describes North Korean hacking as a persistent threat to Korean public and private sectors. The transcript cites Kimsuky phishing with malicious OneNote survey lures, lookalike Naver domains, stolen email accounts, Chromium browser-extension abuse to steal Gmail, and Google account synchronization to push malicious Android apps. It also covers Andariel ransomware and remote-control activity, including exploitation of common vulnerabilities, trojanized X-Popup files, Gh0st RAT deployment through a weaponized tool, and advisory IOCs such as xpopup.pe.kr, xpopup.com, 115.68.95.128, and 11.205.197.111.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 11.205.197.111 | 2024-01-29 | 2024-01-29 |
| DOMAIN | xpopup.com | 2023-02-09 | 2024-01-29 |
| IPv4 | 115.68.95.128 | 2022-09-08 | 2024-01-29 |