한미(독) 합동 보안권고문으로 보는 북의 해킹 활동

2024-01-29 KRNCSC North Korea's hacking activities seen in the ROK-US (Germany) joint security advisory

https://www.ncsc.go.kr:4018/main/cop/bbs/selectBoardArticle.do?bbsId=EducationData_main&nttId=112843&menuNo=070000&subMenuNo=070600&thirdMenuNo=070400

NCSC's discussion of South Korea, U.S., and Germany joint advisories describes North Korean hacking as a persistent threat to Korean public and private sectors. The transcript cites Kimsuky phishing with malicious OneNote survey lures, lookalike Naver domains, stolen email accounts, Chromium browser-extension abuse to steal Gmail, and Google account synchronization to push malicious Android apps. It also covers Andariel ransomware and remote-control activity, including exploitation of common vulnerabilities, trojanized X-Popup files, Gh0st RAT deployment through a weaponized tool, and advisory IOCs such as xpopup.pe.kr, xpopup.com, 115.68.95.128, and 11.205.197.111.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 11.205.197.111 2024-01-29 2024-01-29
DOMAIN xpopup.com 2023-02-09 2024-01-29
IPv4 115.68.95.128 2022-09-08 2024-01-29

Related Reports

« Back