北 해킹 조직, 거래처 업무 메일로 위장한 스피어 피싱 공격 주의!

2025-02-13 ESTSecurity Warning on North Korean Spear-Phishing Disguised as Business Partner Email

https://blog.alyac.co.kr/5526

Thumbnail for 北 해킹 조직, 거래처 업무 메일로 위장한 스피어 피싱 공격 주의!

ESRC reported a spear-phishing campaign in which attackers impersonated business counterparts by abusing reply-chain context and spoofed sender names to make malicious emails appear trustworthy. The emails carried EGG archives containing PIF executables, which displayed decoy PDFs for items such as inspection documents or laptop quotations while launching IconCache.tmp.pif in the background. ESRC identified IconCache.tmp.pif as the PebbleDash backdoor, capable of connecting to attacker-controlled C2 for file download, upload, and execution commands. The C2 server appeared to be a hacked site with an inserted web shell, and ESRC linked the activity to suspected Kimsuky operations based on PebbleDash use and a web shell matching infrastructure previously associated with the group. The case highlights continued use of trusted business-email context, uncommon executable extensions, and decoy documents to improve phishing success against corporate users.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d0a41dfe8f5b5c8ba6a5d0bdc375454… 2025-02-13 2025-05-19
HASH 6744ca5d49833c9b90aee0f3be39d28… 2025-02-13 2025-02-13
HASH dd9607913e9c422d6dcf2e8d11be71a… 2025-02-13 2025-02-13

Related Actors

Related Reports

« Back