국내 그룹웨어 대상 북한 APT 공격 분석
2026-07-22 • ENKI • Analysis of North Korean APT Attacks Targeting South Korean Groupware •
Attachments
source_3852_7RaMRvT.pdf (3 MB)
Enki WhiteHat links a series of compromises at South Korean groupware vendors and their customers to Kimsuky, with attackers exploiting server vulnerabilities and spear-phishing employees to establish initial access. The intrusions deployed Gomir, HttpTroy, BirdTroy, DriveTroy and HelloDoor for remote control, credential theft, reverse proxying and lateral movement into deployment and development servers. Attackers also modified a groupware login page to exfiltrate plaintext credentials and used Google Drive and Cloudflare Tunnel infrastructure for command and control. The investigation identified at least four customers compromised through one vendor's product and five additional victim servers through infrastructure tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://armor-monte-goals-book.… | 2026-07-22 | 2026-07-22 |
| URL | https://detected-rebate-dennis-… | 2026-07-22 | 2026-07-22 |
| DOMAIN | armor-monte-goals-book.trycloud… | 2026-07-22 | 2026-07-22 |
| DOMAIN | detected-rebate-dennis-mortgage… | 2026-07-22 | 2026-07-22 |
| IPv4 | 157.250.203.2 | 2026-07-22 | 2026-07-22 |
| IPv4 | 69.164.254.251 | 2026-07-22 | 2026-07-22 |
| IPv4 | 69.10.48.94 | 2026-07-22 | 2026-07-22 |
| IPv4 | 69.169.103.74 | 2026-07-22 | 2026-07-22 |
| IPv4 | 64.20.44.221 | 2026-07-22 | 2026-07-22 |
| IPv4 | 192.64.83.138 | 2026-07-22 | 2026-07-22 |
| [email protected] | 2026-07-20 | 2026-07-22 | |
| DOMAIN | auth.samecloud.o-r.kr | 2026-07-20 | 2026-07-22 |
| URL | https://auth.samecloud.o-r.kr/i… | 2026-07-20 | 2026-07-22 |
| IPv4 | 163.245.195.172 | 2026-07-20 | 2026-07-22 |
| IPv4 | 208.73.202.29 | 2026-07-20 | 2026-07-22 |
| IPv4 | 69.10.50.165 | 2026-07-20 | 2026-07-22 |