Kimsuky 그룹, 국회의원 선거기간 노린 공격정황 포착
2020-04-10 • Ahnlab • Kimsuky group detects attacks targeting the National Assembly election period •
AhnLab linked an election-period malicious document campaign to Kimsuky, centered on Word documents that contacted saemaeul.mireene[.]com infrastructure previously associated with the group. The initial document contained election-related content but did not reveal it on standalone execution; the source says a second macro-enabled document reconstructed or unlocked the content only in specific conditions, suggesting targeted delivery. The macro chain embedded an edit-unlock password, modified and resaved the decoy document, sent user information to attacker infrastructure, and registered a VBS task to reconnect to configured network addresses every five minutes. AhnLab detected the malicious documents as XML/Dloader and Downloader/Doc.Generic.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | saemaeul.mireene.com | 2020-04-10 | 2020-07-29 |
| DOMAIN | mireene.com | 2020-03-20 | 2020-07-29 |