킴수키(Kimsuky), '사이버 안전국' 메일을 위장한 해킹 시도!

2023-03-14 • ESTSecurity • Kimsuky hacking attempt disguised as a Cyber Safety Bureau email •

https://blog.alyac.co.kr/5102

Thumbnail for 킴수키(Kimsuky), '사이버 안전국' 메일을 위장한 해킹 시도!

ESRC attributes a Korean phishing campaign to Kimsuky, targeting people connected to North Korea-related organizations with email impersonating the Cyber Safety Bureau. The lure claimed the recipient faced legal or account-abuse issues and attached an archive containing a CHM file named for information-network law; running it displayed benign help content while executing a background Click() script. The script stored encoded commands in Document.dat, used Certutil to decode them into Document.vbs, registered persistence through the Run key, and executed PowerShell from ibsq.co.kr to steal user information. The report notes North Korean wording in the email body and lists hashes plus ibsq.co.kr URLs as representative indicators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ibsq.co.kr 2023-03-14 2023-06-09
HASH 4f1081d688ba2477e097ebbbf0cce40… 2023-03-14 2023-05-24
URL http://ibsq.co.kr/config/demo.t… 2023-03-14 2023-05-24
HASH 35cb65a70e8296aafd09b7550b13da2… 2023-03-14 2023-03-14
HASH 7ba620bf5151e68890d818629587cb14 2023-03-14 2023-03-14
URL http://ibsq.co.kr/config/show.p… 2023-03-14 2023-03-14

Related Actors

Related Reports

« Back