Countering threats from North Korea
2022-03-24 • Google •
https://blog.google/threat-analysis-group/countering-threats-north-korea/
Google TAG reported two North Korean government-backed groups exploiting Chrome CVE-2022-0609 before and shortly after the February 2022 patch. One campaign aligned with Operation Dream Job targeted more than 250 people at U.S.-based news media, domain registrar, web hosting, and software vendors using recruiter-themed emails and spoofed job sites that served the exploit kit through hidden iframes. A second Operation AppleJeus campaign targeted more than 85 cryptocurrency and fintech users by compromising fintech sites and using fake cryptocurrency sites to route visitors to the same kit. The exploit chain fingerprinted browsers, served a Chrome RCE when conditions matched, encrypted stages with session-specific keys, and used safeguards such as one-time links and time-limited iframe delivery; TAG noted infrastructure overlap and shared exploit supply-chain indicators among DPRK operators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | indeedus.org | 2022-03-24 | 2022-08-11 |
| DOMAIN | disneycareers.net | 2022-03-24 | 2022-04-26 |
| URL | https://gatexpiring.com/gate/in… | 2022-03-24 | 2022-03-24 |
| URL | https://financialtimes365.com/u… | 2022-03-24 | 2022-03-24 |
| URL | https://humingbot.io/cdn/js.asp | 2022-03-24 | 2022-03-24 |
| URL | https://teenbeanjs.com/cloud/ja… | 2022-03-24 | 2022-03-24 |
| URL | https://varietyjob.com/sitemap/… | 2022-03-24 | 2022-03-24 |
| URL | https://colasprint.com/about/ab… | 2022-03-24 | 2022-03-24 |
| DOMAIN | gatexpiring.com | 2022-03-24 | 2022-03-24 |
| DOMAIN | chainnews-star.com | 2022-03-24 | 2022-03-24 |
| DOMAIN | ziprecruiters.org | 2022-03-24 | 2022-03-24 |
| DOMAIN | teenbeanjs.com | 2022-03-24 | 2022-03-24 |
| DOMAIN | gbclabs.com | 2022-03-24 | 2022-03-24 |
| DOMAIN | onlynova.org | 2022-03-24 | 2022-03-24 |
| DOMAIN | humingbot.io | 2022-03-24 | 2022-03-24 |
| DOMAIN | giantblock.org | 2022-03-24 | 2022-03-24 |
| DOMAIN | financialtimes365.com | 2022-03-24 | 2022-03-24 |
| DOMAIN | varietyjob.com | 2022-03-24 | 2022-03-24 |
| DOMAIN | find-dreamjob.com | 2022-03-24 | 2022-03-24 |
| DOMAIN | colasprint.com | 2021-01-25 | 2022-03-24 |