2022년 상반기 북한 공격 그룹 공격동향 Part.1 : 문서형 기반 악성코드

2022-09-03 Igloo North Korean attack group attack trends in the first half of 2022 Part.1: Document type-based malware

https://www.igloo.co.kr/security-information/2022%eb%85%84-%ec%83%81%eb%b0%98%ea%b8%b0-%eb%b6%81%ed%95%9c-%ea%b3%b5%ea%b2%a9-%ea%b7%b8%eb%a3%b9-%ea%b3%b5%ea%b2%a9%eb%8f%99%ed%96%a5-part-1-%eb%ac%b8%ec%84%9c%ed%98%95-%ea%b8%b0%eb%b0%98/

Thumbnail for 2022년 상반기 북한 공격 그룹 공격동향 Part.1 : 문서형 기반 악성코드

IGLOO analyzes document-based malware activity linked in the source to North Korean attack groups active in the first half of 2022, including Kimsuky and Lazarus. The activity used spear-phishing themes such as defector-related surveys, disaster donation receipts, cryptocurrency topics, and press-release lures to target Korean public and private-sector audiences. HWP samples hid shellcode in OLE objects, used zlib-encoded data, launched batch and PowerShell logic, terminated HWP processes, and displayed decoy documents to mask execution. DOC samples abused macros or Office exploit paths to download payloads, run backdoors packed with Themida, collect host and user information, inject code into WinWord or explorer.exe, and abuse Windows Update components and GitHub storage for execution or communications. The repeated use of spear-phishing, OLE or macro execution, DLL-based payloads, Base64 obfuscation, and living-off-the-land Windows processes shows a mature document-malware tradecraft pattern relevant to Korean targets and cryptocurrency-related theft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 905745e2a196d7f8d7c2f9547f5b9e67 2022-07-25 2022-09-03

Related Actors

Related Reports

« Back