2021년 김수키 그룹은 어떻게 움직였나

2022-03-07 Ahnlab How the Kimsuky Group Operated in 2021

https://www.ahnlab.com/kr/site/securityinfo/secunews/secuNewsView.do?curPage=&menu_dist=2&seq=31442&key=&dir_group_dist=&dir_code=

Thumbnail for 2021년 김수키 그룹은 어떻게 움직였나

Kimsuky is assessed in the excerpt as a North Korea-backed APT focused on information theft, with 2021 activity continuing against defense, diplomacy, unification-related personnel, and reported energy and aerospace victims in South Korea. The group shifted from mainly weaponized Hangul documents toward malicious Microsoft Office files, while still using familiar lure themes such as manuscript payments, COVID-19, and official-looking documents. The activity included smishing and a KISA mobile antivirus-themed Android APK that collected sensitive device data, exfiltrated it to C&C infrastructure, and enabled remote control. Reported malware and tooling included AppleSeed JavaScript and Android variants, FlowerPower PowerShell keylogging, CVE-2020-9715 PDF exploitation, PebbleDash, and BravePrince variants with changed communications, encryption, and collection routines. The report matters because it shows Kimsuky adapting document formats, mobile delivery, malware variants, and exploit use while continuing long-running targeting patterns.

Related Actors

Related Reports

« Back