Countering threats from North Korea

2022-03-24 Google

https://blog.google/threat-analysis-group/countering-threats-north-korea/

Thumbnail for Countering threats from North Korea

Google TAG reported two North Korean government-backed groups exploiting Chrome CVE-2022-0609 before and shortly after the February 2022 patch. One campaign aligned with Operation Dream Job targeted more than 250 people at U.S.-based news media, domain registrar, web hosting, and software vendors using recruiter-themed emails and spoofed job sites that served the exploit kit through hidden iframes. A second Operation AppleJeus campaign targeted more than 85 cryptocurrency and fintech users by compromising fintech sites and using fake cryptocurrency sites to route visitors to the same kit. The exploit chain fingerprinted browsers, served a Chrome RCE when conditions matched, encrypted stages with session-specific keys, and used safeguards such as one-time links and time-limited iframe delivery; TAG noted infrastructure overlap and shared exploit supply-chain indicators among DPRK operators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN indeedus.org 2022-03-24 2022-08-11
DOMAIN disneycareers.net 2022-03-24 2022-04-26
URL https://gatexpiring.com/gate/in… 2022-03-24 2022-03-24
URL https://financialtimes365.com/u… 2022-03-24 2022-03-24
URL https://humingbot.io/cdn/js.asp 2022-03-24 2022-03-24
URL https://teenbeanjs.com/cloud/ja… 2022-03-24 2022-03-24
URL https://varietyjob.com/sitemap/… 2022-03-24 2022-03-24
URL https://colasprint.com/about/ab… 2022-03-24 2022-03-24
DOMAIN gatexpiring.com 2022-03-24 2022-03-24
DOMAIN chainnews-star.com 2022-03-24 2022-03-24
DOMAIN ziprecruiters.org 2022-03-24 2022-03-24
DOMAIN teenbeanjs.com 2022-03-24 2022-03-24
DOMAIN gbclabs.com 2022-03-24 2022-03-24
DOMAIN onlynova.org 2022-03-24 2022-03-24
DOMAIN humingbot.io 2022-03-24 2022-03-24
DOMAIN giantblock.org 2022-03-24 2022-03-24
DOMAIN financialtimes365.com 2022-03-24 2022-03-24
DOMAIN varietyjob.com 2022-03-24 2022-03-24
DOMAIN find-dreamjob.com 2022-03-24 2022-03-24
DOMAIN colasprint.com 2021-01-25 2022-03-24

Related Actors

Related Reports

« Back