ESTsecurity (CEO Chung Sang-won), a security specialist, said on the 18th that North Korea-linked hacking attacks disguised as the February issue of the Ministry of Unification's chronology of inter-Korean relations are being found one after another, and that particular care is required.
The attack cunningly posed as a chronology of inter-Korean relations sent officially by the Ministry of Unification, targeting experts and workers in the North Korea field, and was revealed to be aimed at stealing email accounts. It partly imitated the design of actual Ministry of Unification screens to look legitimate, and was characterized by making it appear that a file named 'Chronology_of_inter-Korean_relations(February 2022).hwp' was attached at the bottom of the body.
According to analysis by ESTsecurity's Security Response Center (ESRC), many similar cases of this technique were detected from 2020 through last year, and the type that lures recipients with content related to North Korean material — the Ministry of Unification's North Korea trends or the Korea Institute for National Unification's outlook for the Korean Peninsula, for example — continues to be reported steadily.
The hacking attacks use the technique of elaborately faking the sender address to look like the official addresses of the Ministry of Unification, the Korea Institute for National Unification or the Institute for National Security Strategy so that recipients do not become suspicious; approaching an attachment carelessly, trusting the sender address as it appears to the eye, can lead to unexpected hacking damage.
According to ESRC's analysis, the attack found this time may look like a typical spear phishing attack inducing recipients to open a malicious HWP document attached to the email body, but it is in fact an attack aimed at stealing portal account credentials by inserting a malicious URL link rather than an attachment.
If the attachment link is clicked, instead of the document downloading directly, a screen appears asking the recipient to enter their portal account password; once a valid password is entered a legitimate HWP document is shown, making it hard for the user to realize they have been exposed to a hack.
Moreover, if the password is leaked, the possibility of covert and continuous personal information leakage cannot be ruled out, nor can the risk that the attacker will use the victim's account without authorization to approach people they know, turning the victim into a secondary source of harm.
Since the attack uses the deception of leaking account credentials the moment a password is entered while simultaneously displaying a legitimate document so the victim does not realize they have been hacked, careful attention is needed: check closely whether the document shown is actually registered on the official site, and do not be taken in.
ESRC Director Moon Jong-hyun said: "Because North Korea-linked cyber threats impersonating particular Korean institutions or private-sector services are escalating, this is a time when watertight efforts to strengthen cybersecurity are needed," adding, "To respond to North Korea's all-out cyber offensive in particular, building a closer and more coordinated public-private cooperation system is essential."
ESTsecurity, meanwhile, is closely sharing related cyber threat information with the Korea Internet & Security Agency (KISA) and other relevant authorities, maintaining cooperation to prevent known threats from spreading.