Operation (노스 스타) North Star A Job Offer That’s Too Good to be True?

2020-07-29 Mcafee Operation North Star: a job offer that is too good to be true

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/operation-north-star-a-job-offer-thats-too-good-to-be-true/

McAfee ATR observed a 2020 Operation North Star activity set using malicious job-offer documents to target aerospace and defense interests and install data-gathering implants. The activity used legitimate defense-contractor job postings as lures, template injection in Office documents to fetch remote DOTM templates, and Visual Basic macros that loaded DLL implants on victim systems. McAfee linked the 2020 indicators and TTPs to prior 2017 and 2019 activity attributed by the U.S. government to Hidden Cobra, the North Korea-linked umbrella that includes Lazarus, Kimsuky, KONNI, and APT37. The campaign used compromised infrastructure across multiple European countries for command and control and implant distribution, supporting victim identification and intelligence collection against strategically sensitive sectors.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN orblog.mireene.com 2020-07-29 2023-10-30
DOMAIN mireene.com 2019-05-10 2023-10-30
DOMAIN elite4print.com 2020-04-28 2022-09-29
HASH 02e319af73a33547343b71d5cb1064bc 2020-07-29 2020-12-15
DOMAIN nhpurumy.mireene.com 2020-03-20 2020-11-02
DOMAIN jmable.mireene.com 2019-05-10 2020-11-02
HASH 7933716892e0d6053057f5f2df0ccad… 2020-07-29 2020-08-19
HASH 6a3446b8a47f0ab4f536015218b2265… 2020-07-29 2020-08-19
HASH 35577959f79966b01f520e2f0283969… 2020-07-29 2020-07-29
HASH d1e2a9367338d185ef477acc4d91ad4… 2020-07-29 2020-07-29
HASH f3847f5de342632f8f9e2901f16b712… 2020-07-29 2020-07-29
HASH 659c854bbdefe692ee8c52761e7a8c7… 2020-07-29 2020-07-29
HASH 83878c91171338902e0fe0fb97a8c47a 2020-07-29 2020-07-29
HASH 70f66e3131cfbda4d2b82ce9325fed7… 2020-07-29 2020-07-29
HASH 16d421807502a0b2429160e0bd960fa… 2020-07-29 2020-07-29
HASH 49724ee7a6baf421ac5a2a3c93d32e7… 2020-07-29 2020-07-29
HASH ecbe46ca324096fd5e35729f39fa3bd… 2020-07-29 2020-07-29
HASH dbbdcc944c4bf4baea92d1c1108e055… 2020-07-29 2020-07-29
HASH 81249fe1b8869241374966335fd912c… 2020-07-29 2020-07-29
HASH 43b6b0af744124da5147aba81a98bc7… 2020-07-29 2020-07-29
HASH 322aa22163954ff3ff017014e357b75… 2020-07-29 2020-07-29
HASH 975ae81997e6cd8c8a3901308d33c86… 2020-07-29 2020-07-29
HASH bff1d06b9ef381166de55959d73ff93b 2020-07-29 2020-07-29
HASH adcdbec0b92da0a39377f5ab95ffe9b… 2020-07-29 2020-07-29
HASH a3eca35d14b0e020444186a5faaba59… 2020-07-29 2020-07-29
HASH df5536c254a5d9ac626dbff7525de83… 2020-07-29 2020-07-29
HASH acefc63a2ddbbf24157fc102c6a11d6… 2020-07-29 2020-07-29
HASH 13c47e19182454efa60890656244ee1… 2020-07-29 2020-07-29
HASH 40fbac7a241bea412734134394ca81c… 2020-07-29 2020-07-29
HASH 4a08c391f91cc72de7a78b5fd5e7f74… 2020-07-29 2020-07-29
URL https://www.ne-ba.org/files/gal… 2020-07-29 2020-07-29
URL https://www.anca-aste.it/upload… 2020-07-29 2020-07-29
URL https://web.opendrive.com/api/v… 2020-07-29 2020-07-29
URL http://saemaeul.mireene.com/ski… 2020-07-29 2020-07-29
DOMAIN jmdesign.mireene.com 2020-07-29 2020-07-29
DOMAIN web.opendrive.com 2020-07-29 2020-07-29
DOMAIN all200.mireene.com 2020-07-29 2020-07-29
DOMAIN sgmedia.mireene.com 2020-07-29 2020-07-29
HASH 1b0c82e71a53300c969da61b085c8ce… 2020-05-15 2020-07-29
HASH 66e5371c3da7dc9a80fb4c0fabfa23a… 2020-05-15 2020-07-29
HASH bff4d04caeaf8472283906765df3442… 2020-05-15 2020-07-29
HASH b76b6bbda8703fa801898f843692ec1… 2020-05-15 2020-07-29
HASH 48b8486979973656a15ca902b7bb973… 2020-05-15 2020-07-29
HASH d7ef8935437d61c975feb2bd826d018… 2020-05-15 2020-07-29
HASH 37a3c01bb5eaf7ecbcfbfde1aab8489… 2020-05-15 2020-07-29
URL http://www.elite4print.com/admi… 2020-05-15 2020-07-29
URL https://www.sanlorenzoyacht.com… 2020-05-15 2020-07-29
URL https://www.astedams.it/uploads… 2020-05-08 2020-07-29
URL https://od.lk/d/MzBfMjA1Njc0ODd… 2020-04-30 2020-07-29
URL https://www.sanlorenzoyacht.com… 2020-04-30 2020-07-29
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-07-29
URL http://saemaeul.mireene.com/ski… 2020-04-10 2020-07-29
DOMAIN saemaeul.mireene.com 2020-04-10 2020-07-29
DOMAIN vnext.mireene.com 2020-03-20 2020-07-29

Related Reports

« Back