2019년 북한 신년사 평가로 위장한 '오퍼레이션 엔케이 뉴이어(Operation NK New Year)' APT 사이버 위협 등장
2019-01-03 • ESTSecurity • APT cyber threat emerges under 'Operation NK New Year' disguised as an evaluation of North Korea's 2019 New Year's address •
ESRC analyzed a 2019 APT lure built around a document titled as an assessment of North Korea's New Year address and noted code similarities to the 2014 Korea Hydro & Nuclear Power attack. The executable carried a normal HWP decoy and 32-bit/64-bit malicious DLL resources disguised as HncChecker.dll, dropping into C:\ProgramData\Hnc\ to resemble legitimate document software components. The malware logged infection activity, captured keystrokes into userdata.cab, and attempted to transmit collected data through a Korean portal webmail service. ESRC connected the TTPs to continuing attacks against South Korea involving diplomatic, security, and unification themes, making the case useful for detecting document-themed espionage and keylogging activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | serial.info | 2019-01-03 | 2019-01-03 |