2차 북미정상회담 좌담회 초청으로 수행된 최신 APT 공격, '작전명 라운드 테이블(Operation Round Table)'

2019-02-21 ESTSecurity The latest APT attack, 'Operation Round Table', was carried out at the invitation of the 2nd North Korea-US summit roundtable.

https://blog.alyac.co.kr/2140

Thumbnail for 2차 북미정상회담 좌담회 초청으로 수행된 최신 APT 공격, '작전명 라운드 테이블(Operation Round Table)'

ESRC reported a 21 February 2019 spear-phishing attack using a malicious HWP document themed around the planned second U.S.–North Korea summit in Hanoi. The document contained a BIN0003.eps PostScript stream that exploited an HWP EPS vulnerability and embedded shellcode. The shellcode contacted itoassn.mireene.co.kr/shop/shop/mail/com/mun/down[.]php, retrieved encrypted data disguised as a PNG, and wrote ~emp.dll in a temporary folder to run further commands. ESRC linked the tradecraft to Operation Black Limousine and to shellcode patterns seen in earlier Korea-focused APT activity, including the KHNP intrusion cluster.

« Back