ESTsecurity (CEO Jung Jin-il), a security company, warned on the 26th that a North Korea-linked hacking attack disguised as an invitation to the '2022 Institute of Foreign Affairs and National Security (IFANS) international conference' has appeared, urging particular care.
The attack used as bait a real event scheduled for November 2 at the Korea National Diplomatic Academy's Institute of Foreign Affairs and National Security (IFANS), employing an interesting technique that lures experts in diplomacy, security and defense into completing a Google form as if being invited.
The international conference is an annual forum of IFANS at the Korea National Diplomatic Academy, a discussion event that contributes to diplomatic strategy by bringing together and analyzing the views and forecasts of leading Korean and international academics and experts in diplomacy, security and defense. The attacker was found to have stolen the invitation image attached to the '2022 IFANS International Conference' notice posted on the Ministry of Foreign Affairs' official website on October 21 and used it in the attack.
The invitation image is included in the body of a phishing email; if the recipient clicks the image area, they are taken to a phishing site. What appears looks like a Google form, but the destination is the address 'docxooqle.epizy[.]com'. A closer look at the site reveals it to be a fake disguised as Google.
ESTsecurity's Security Response Center (ESRC) investigated the phishing technique disguised as a Google form and found that the attacker had carefully imitated the real Google form format for the attack.
In particular, it attempts a first round of information theft by having the target enter personal details directly — name, affiliation, position, email and contact number — under the guise of survey fields. Once the form is submitted, the screen moves to the phishing address 'accounts.qocple.epizy[.]com', showing a Google login screen and going on to steal the Gmail password.
This can lead to a chain of harm, from the leak of key personal information to Google account passwords, so careful attention is needed, along with the security habit of checking closely whether the site you visit is the official address.
The 'epizy[.]com' domains found repeatedly here belong to 'Infinity Free', an overseas free web hosting service that has been appearing consistently in recent North Korea-linked hacking incidents, in a threat campaign known as 'Fake Striker'.
ESRC noted that the first-stage Google form phishing was designed to make personal information theft relatively easy, and that the second-stage Google login screen was in English rather than Korean — suggesting the targets are likely to be people familiar with English-language services.
With mounting evidence that the attack targeted Google Gmail users in particular, users should maintain secondary authentication such as OTP, and make passwords complex with special characters and mixed case, changing them regularly.
ESTsecurity Director Moon Jong-hyun said: "It is not that threats disguised as Google forms were unheard of in the past, but it is rare to see Google phishing used with a technique this sophisticated," adding, "The level of cybersecurity threat attributed to North Korea is continuing to run high in the second half of this year," and urging thorough security precautions.
ESTsecurity is working closely with the Korea Internet & Security Agency (KISA) and other relevant authorities on measures to prevent the spread of similar harm.