North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets

2021-11-10 Cisco Talos

https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html

Thumbnail for North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets

Cisco Talos attributes a campaign active since at least June 2021 to Kimsuky, targeting South Korean geopolitical, diplomatic, military, and aerospace research organizations. The attackers used malicious Blogspot pages reached from Office maldocs to stage beacons, file exfiltrators, and implant deployment scripts. Follow-on payloads included Gold Dragon/Brave Prince-derived modules for system information theft, keylogging, credential stealing, file injection, and reconnaissance. Talos cites code similarity, macro overlap, shared metadata, and infrastructure links to previous Kimsuky activity, including a known Kimsuky URL at eucie09111[.]myartsonline[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dddc57299857e6ecb2b80cbab2ae6f1… 2021-11-10 2024-04-23
HASH 5498c3eb2fb335aadcaf6c5d60560c5… 2021-11-10 2022-08-30
DOMAIN o61666ch.getenjoyment.net 2021-11-10 2022-08-25
HASH 5e3907e9e2ed8ff12bb4e96b52401d8… 2021-11-10 2021-12-30
HASH 85f6db3a74a4f1a367cc0b60b190c5d… 2021-11-10 2021-11-10
HASH 4b0e2244f82170f4e569bb6b100890e… 2021-11-10 2021-11-10
HASH de0932206c4d531ab4325c0ec8f0251… 2021-11-10 2021-11-10
HASH 99b516acd059a4b88f281214d849c51… 2021-11-10 2021-11-10
HASH 395eebf586d5fc033e22235f7a4224e… 2021-11-10 2021-11-10
HASH e929f23c242cc102a16f54661636225… 2021-11-10 2021-11-10
HASH 595be57cb6f025ec5753fbe72222e3f… 2021-11-10 2021-11-10
HASH bb0a3c784e55bd25f845644b69c57e3… 2021-11-10 2021-11-10
HASH 5563599441935e3c0c8bdd42ec2c35b… 2021-11-10 2021-11-10
HASH 873b8fb97b4b0c6d7992f6af1565329… 2021-11-10 2021-11-10
HASH f4d06956085d2305c19dd78c6d01b06… 2021-11-10 2021-11-10
HASH c43475601f330a5a17a50f075696e05… 2021-11-10 2021-11-10
HASH 048f3564d5c4d3e0e3b879f33f3b8d3… 2021-11-10 2021-11-10
HASH 4b244ac09e4b46792661754bd5d386e… 2021-11-10 2021-11-10
HASH 36187cd4bc18e4d6ddc5c96dc0ed038… 2021-11-10 2021-11-10
DOMAIN pcsecucheck.scienceontheweb.net 2021-11-10 2021-11-10
URL http://eucie09111.myartsonline.… 2021-07-26 2021-11-10
DOMAIN eucie09111.myartsonline.com 2021-07-26 2021-11-10
HASH 811b42bb169f02d1b0b3527e2ca6c00… 2021-06-09 2021-11-10

Related Actors

Related Reports

« Back