Kimsuky 그룹, 국회의원 선거기간 노린 공격정황 포착

2020-04-10 Ahnlab Kimsuky group detects attacks targeting the National Assembly election period

https://asec.ahnlab.com/1313

Thumbnail for Kimsuky 그룹, 국회의원 선거기간 노린 공격정황 포착

AhnLab linked an election-period malicious document campaign to Kimsuky, centered on Word documents that contacted saemaeul.mireene[.]com infrastructure previously associated with the group. The initial document contained election-related content but did not reveal it on standalone execution; the source says a second macro-enabled document reconstructed or unlocked the content only in specific conditions, suggesting targeted delivery. The macro chain embedded an edit-unlock password, modified and resaved the decoy document, sent user information to attacker infrastructure, and registered a VBS task to reconnect to configured network addresses every five minutes. AhnLab detected the malicious documents as XML/Dloader and Downloader/Doc.Generic.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN saemaeul.mireene.com 2020-04-10 2020-07-29
DOMAIN mireene.com 2020-03-20 2020-07-29

Related Actors

Related Reports

« Back