ESTsecurity (CEO Chung Sang-won), a security specialist, said on the 4th that a North Korea-linked hacking attack disguised as the issuance of a hospital or medical center certificate has appeared in Korea, and that particular care and preparation are required.
The attack distributed malicious files cunningly disguised as an online health checkup result lookup and issuance service, and was characterized by a trust-based deception that bundled in the legitimate plug-in program actually needed to issue certificates at Korean hospitals and medical institutions.
So when the program is installed, a legitimate hospital certificate can indeed be issued — but the user is simultaneously exposed to an unexpected cybersecurity threat.
According to analysis by ESTsecurity's Security Response Center (ESRC), the malicious file was created on February 25 but the attack itself was carried out in March, and it was developed for 64-bit Windows.
Inside the file are two resources, each in encrypted form: one is the legitimate hospital certificate issuance program, the other a malicious file that covertly performs backdoor functions. With this structure both the malicious and the legitimate module are installed at once, but only the legitimate installation screen appears on the computer.
Through similarity and correlation analysis of the malicious files found, ESRC officially confirmed the attack as an extension of the APT (advanced persistent threat) attack carried out in February against reporters at a Korean terrestrial broadcaster and North Korea-focused media outlets using a file named 'In-house financial affairs details.zip', and of the attack impersonating an annual report by the Japan Institute of International Affairs, a Japanese diplomatic and security think tank, on rising military tension in Northeast Asia and Japan's response strategy.
Among the threat indicators found in that attack on the Korean broadcaster were distinctive traces including the North Korean-style word 'hyeonsi', the 'Freehunter' account used by the attacker, and the command-and-control (C2) server 'ms-work[.]com-info[.]store'. Notably, the initials 'KGH' were found in the compromise linked to that threat.
The C2 server used in this attack is the domain 'ms-work[.]com-pass[.]online', similar to the address in the attack on that broadcaster, and the key function structures were analyzed as matching too. A variant found around July 2021 also disguised itself as an extension for the Whale browser, and used the export function name 'KGH_Backdoor.dll' and the address 'support-hosting[.]000webhostapp[.]com'.
ESRC is examining various material in which the 'KGH' keyword is used in account or folder names, and is conducting a close investigation into who is behind the threat, keeping every possibility in mind including that they are someone's initials. Among similar threats, a history of access to a particular overseas service from a North Korean IP address around 2012 has been reported.
ESTsecurity ESRC head Moon Jong-hyun said: "With many data-destroying malicious files attributed to Russia being reported in Ukraine, North Korea-linked cyber threats are also being found steadily in Korea," adding that social engineering hacking attacks could appear in connection with the coming Korean presidential election and urging particular care and preparation.
ESTsecurity, meanwhile, has completed an update covering the related malicious files in its ALYac antivirus program, and is closely sharing cyber threat information with the Korea Internet & Security Agency (KISA) and other relevant authorities to prevent known threats from spreading.