ESTsecurity (CEO Jung Jin-il), a security specialist, said on the 15th that a hacking attack disguised as a presentation paper for the unification policy forum marking the 22nd anniversary of the June 15 Inter-Korean Joint Declaration has been found, and that those concerned should take particular care.
The threat was disguised as material related to a unification policy forum prepared to assess the new administration's direction on North Korea and unification policy and to explore inter-Korean peace. The forum is indeed being held on June 15 at the Korea Press Center, with experts in diplomacy, security, unification and North Korea taking part as presenters and discussants.
The attack used a typical email phishing technique: the screen was made to look as though a document named 'The new geopolitics of Northeast Asia and Korea's options.hwp' was attached via the cloud, and the email impersonated a professor at the Institute of Foreign Affairs and National Security of the Korea National Diplomatic Academy who is attending the forum as a presenter.
If the recipient clicks the attachment, a phishing site hosted overseas appears, displaying the message [Authentication is required to download the cloud file] to make the victim less suspicious. It then prompts them to enter the password for the portal email they use.
The address used for the phishing site, 'kakao[.]cloudfiles[.]epizy[.]com', might at a glance be passed over as a portal cloud attachment link, but a closer look quickly shows it is entirely unrelated. The 'epizy[.]com' domain used in the phishing is the address of an overseas free web hosting service known as 'Infinity Free', which is being found continually in North Korea-linked phishing cases.
Addresses similar in form to this phishing address have been found, including 'naver[.]cloudfiles[.]epizy[.]com', 'snu[.]cloudfiles[.]epizy[.]com', 'korea[.]onedviver[.]epizy[.]com' and 'yonsei[.]onedviver[.]epizy[.]com'. Typically they impersonate the domains of Korean portal companies or particular universities; where a university address was imitated, the attacks were found to concentrate on the email accounts of faculty teaching in diplomacy, security and unification.
Advanced persistent threat (APT) attacks based on malicious DOC or HWP OLE have been on the rise recently. With email phishing manipulated to look like large files or cloud-based attachments being reported steadily among them, users need to pay closer attention and care so as not to be exposed to similar security threats.
According to analysis by ESTsecurity's Security Response Center (ESRC), attacks abusing overseas free web hosting have been in continuous use for several years and are found mainly in the North Korea-linked 'Fake Striker' threat campaign. Besides 'Infinity Free', these actors also alternate with an overseas service called 'Web Free Hosting' that offers a range of domain addresses.
What these attacks have in common recently is that an actual legitimate document is delivered immediately after the password is stolen, so victims do not easily realize they have been hacked and the scope of harm widens as time passes.
According to ESRC, this attack too switches to a particular Google Drive address after the password entry step and shows the document. Notably, the name 'kisa' was used in common in the last-saved information of the malicious and legitimate documents found in similar recent attacks. Analysis showed that the various threat cases using the name 'kisa' all match precisely the Fake Striker campaign attributed to North Korea, and close observation and investigation of the attack's intent is currently under way.
ESRC Director Moon Jong-hyun said: "In June too, cybersecurity threats attributed to North Korea have continued steadily, reaching beyond the diplomacy, security, unification and defense fields to private individuals working in particular sectors," adding, "With North Korea-backed mobile attacks targeting Android smartphone users also being reported, far more attention and investment in strengthening cybersecurity is urgently needed."
ESTsecurity's ESRC, meanwhile, is closely sharing related cyber threat information with the Korea Internet & Security Agency (KISA) and other relevant authorities, maintaining cooperation to prevent known threats from spreading.