ESTsecurity (CEO Jung Jin-il), an integrated security company, said that numerous signs of cyber threats targeting Korean defense contractors have been detected while the Korea-US joint military exercises are under way, and urged the companies concerned to take particular care as the danger level rises by the day.
The attack was first detected on the 22nd, when the joint exercises began, in a form disguised as a program for looking up a computer's IP and MAC address. When the file runs it does output the computer's actual network information, but in the background it covertly plants a malicious DLL module with backdoor functionality, attempting to collect internal information and exfiltrate it.
After first detecting the attack, ESTsecurity's Security Response Center (ESRC) recognized that similar variant attacks were continuing to increase, and analysis confirmed that all of them exchange malicious commands with the same US-based IP address (216.189.154[.]6).
Apparently judging that disguising the attack as a network program with an executable (EXE) extension, as in the earlier case, had limited effect, the attacker then resumed script-based (JSE, VBS) attacks with doubled extensions to make files look like PDF or XLSM documents. It also emerged that the attacker used the executable (PIF) extension technique, which commonly appears as a shortcut (LNK) icon.
The threats detected this time share almost identical malicious patterns, and it is notable that internal business documents and phrasing related to Korean defense contractors were used as bait. In particular, some of the legitimate files shown immediately after the malicious file runs were found to be encrypted with a Korean document security solution (DRM), leading some to argue that the relevant authorities need to investigate closely whether internal material already stolen is being reused in follow-up attacks.
ESRC said its investigation found this to be an extension of the so-called 'Blue Estimate' advanced persistent threat (APT) campaign, which has for several years persistently attacked the defense sector and defense contractors, pharmaceutical companies researching the coronavirus and bitcoin exchanges, explaining that North Korea's Reconnaissance General Bureau is widely known to be behind it.
Besides attacks using malicious files, a phishing address manipulated to look like a defense contractor's internal network login service was also found; the attacker had built it to closely imitate the design of the real website. On closer inspection, though, clear differences from the legitimate site exist, and looking carefully at the official URL address in particular can help determine whether a site is genuine.
An ESTsecurity ESRC representative said: "With the Korea-US joint military exercises under way, the level of North Korean cyber threat aimed at Korean defense contractors is growing bolder and more intense," urging care and adding, "Private-sector specialists working in the defense field need to recognize that they can be exposed to North Korean cyber threats at any time and to maintain a thorough cybersecurity posture at all times."
ESTsecurity has issued an emergency update adding detection of the newly discovered malicious files to its ALYac product, and is working closely with the Korea Internet & Security Agency (KISA) and other relevant authorities on measures to prevent the spread of harm.