6·15 남북공동선언기념 통일정책포럼 발제문으로 위장한 北 연계 해킹 주의

2022-06-15 ESTSecurity Beware of North Korean-linked hacking disguised as a presentation at the Unification Policy Forum commemorating the June 15 Inter-Korean Joint Declaration

https://blog.alyac.co.kr/4796

Thumbnail for 6·15 남북공동선언기념 통일정책포럼 발제문으로 위장한 北 연계 해킹 주의

ESRC reported a North Korea-linked phishing attack disguised as material for a June 15 Inter-Korean Joint Declaration unification policy forum. The lure impersonated a professor and presented a cloud attachment for a supposed HWP document, then redirected victims to a phishing site requiring portal credentials before showing a legitimate Google Drive document. The infrastructure used kakao.cloudfiles.epizy[.]com, part of a pattern of epizy[.]com and similar free hosting domains abused in North Korea-linked Fake Striker cases. Targeting focused on diplomacy, security, unification, defense, academia, and related private-sector individuals. The activity matters because it combines timely policy-event social engineering with cloud-file impersonation and credential theft against communities central to Korean Peninsula policy.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN naver.cloudfiles.epizy.com 2022-06-15 2023-04-18
DOMAIN kakao.cloudfiles.epizy.com 2022-06-15 2023-04-18
DOMAIN snu.cloudfiles.epizy.com 2022-06-15 2023-04-18
DOMAIN epizy.com 2020-09-04 2023-04-18
DOMAIN korea.onedviver.epizy.com 2022-06-15 2022-06-15
DOMAIN yonsei.onedviver.epizy.com 2022-06-15 2022-06-15

Related Reports

« Back