ESTsecurity (CEO Jung Jin-il), a security specialist, said on the 7th that hacking emails exploiting various social concerns and anxieties are being distributed in large volumes in Korea, and that users should take particular care.
ESTsecurity's Security Response Center (ESRC) has confirmed that since March 25 hacking emails attaching malicious Word (DOC) document files with names designed to arouse users' interest and anxiety — such as 'Notice to attend regarding investigation of a COVID-19 quarantine rule violation case' and 'Emergency disaster relief fund application form' — have been distributed in large volumes in Korea.
The attacks were identified as an extension of the 'attack impersonating the Korea Internet Information Center (KRNIC)' that ESRC disclosed on March 25, and the Word files attached to the emails were analyzed as a type that uses malicious macro commands in common.
The attacker induces the recipient to press the [Enable Content] button to activate the malicious macro; pressing it displays the actual document, hiding as far as possible the fact that they have been exposed to a threat. In some attacks, however, a simple deception strategy was used, showing garbled text as though the document's content were corrupted.
If the malicious macro is allowed, communication takes place with a command-and-control (C2) server designated by the attacker and additional malicious files are installed without the user's knowledge. It then collects ▲the user name, ▲the type of antivirus program, ▲the operating system type and ▲system version information, and attempts to exfiltrate them covertly.
Because this first round of exfiltrated information provides the groundwork for staged follow-up attacks, particular care is always needed when checking email, and it is very important not to allow the [Enable Content] button in Word or Excel documents, for security reasons.
ESTsecurity's ALYac antivirus program currently detects this malware as 'Trojan.Downloader.DOC.Gen' and the like, and is responding continuously to further variants.
An ESRC representative said: "The techniques in hacking emails distributed by cyber threat groups are becoming ever more sophisticated and cunning," urging users to take care and adding, "The unauthorized exfiltration of PC information from an unspecified number of users through hacking emails can be seen as a preliminary stage that may lead to unexpected further harm."
ESTsecurity, meanwhile, is closely sharing related cyber threat information with the Korea Internet & Security Agency (KISA) and other relevant authorities, maintaining cooperation to prevent known threats from spreading.