6·15 남북공동선언기념 통일정책포럼 발제문으로 위장한 北 연계 해킹 주의
2022-06-15 • ESTSecurity • Beware of North Korean-linked hacking disguised as a presentation at the Unification Policy Forum commemorating the June 15 Inter-Korean Joint Declaration •
ESRC reported a North Korea-linked phishing attack disguised as material for a June 15 Inter-Korean Joint Declaration unification policy forum. The lure impersonated a professor and presented a cloud attachment for a supposed HWP document, then redirected victims to a phishing site requiring portal credentials before showing a legitimate Google Drive document. The infrastructure used kakao.cloudfiles.epizy[.]com, part of a pattern of epizy[.]com and similar free hosting domains abused in North Korea-linked Fake Striker cases. Targeting focused on diplomacy, security, unification, defense, academia, and related private-sector individuals. The activity matters because it combines timely policy-event social engineering with cloud-file impersonation and credential theft against communities central to Korean Peninsula policy.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | naver.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | kakao.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | snu.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | epizy.com | 2020-09-04 | 2023-04-18 |
| DOMAIN | korea.onedviver.epizy.com | 2022-06-15 | 2022-06-15 |
| DOMAIN | yonsei.onedviver.epizy.com | 2022-06-15 | 2022-06-15 |