PULSE NAME
North Korean Hacking Groups Stealing Construction and Machinery Sector Technologies: A Warning
WHITE Kimsuky and Andariel AlienVault 2024-08-06 Modified: 2024-09-05
23
IOCs
MEDIUM VOLUME
South Korea's cybersecurity community, consisting of the National Intelligence Service, Prosecution Service, Police Agency, Defense Security Command, and Cyber Command, among others, warns of the risks posed by North Korean hacking groups' cyber attacks targeting the domestic construction and machinery sectors. The report highlights the attack strategies, techniques, procedures (TTPs), and indicators of compromise (IoCs) employed by these North Korean groups. As North Korea accelerates its regional development initiatives, its party, military, and government entities, as well as hacking groups, are intensifying efforts to obtain unauthorized access to South Korea's construction, machinery, and urban development data to aid in industrial plant construction and local development plans.
Indicators of Compromise (23)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 19c2decfa7271fa30e48d4750c1d18c1 2024-08-06
FileHash-SHA1 e6be97ca9e79b45c671c6531908f70b353d47994 2024-08-06
FileHash-SHA256 6eebb5ed0d0b5553e40a7b1ad739589709d077aab4cbea1c64713c48ce9c96f9 2024-08-06
FileHash-MD5 094f9a757c6dbd6030bc6dae3f8feab3 2024-08-06
FileHash-MD5 5df3c3e1f423f1cce5bf75f067d1d05c 2024-08-06
FileHash-MD5 afc5a07d6e438880cea63920277ed270 2024-08-06
FileHash-MD5 c8e7b0d3b6afa22e801cacaf16b37355 2024-08-06
FileHash-MD5 d92a317ef4d60dc491082a2fe6eb7a70 2024-08-06
FileHash-MD5 fee610058c417b6c4b3054935b7e2730 2024-08-06
FileHash-SHA1 3d1731fa03f2bb8b3ca74ab49c83923428e58362 2024-08-06
FileHash-SHA256 955cb4f01eb18f0d259fcb962e36a339e8fe082963dfd9f72d3851210f7d2d3b 2024-08-06
domain coolsystem.co.kr 2024-08-06
domain ncsc.go.kr 2024-08-06
domain selectboardarticle.do 2024-08-06
hostname aerosp.p-e.kr 2024-08-06
hostname appofficer.kro.kr 2024-08-06
hostname kmobile.bestunif.com 2024-08-06
hostname kostin.p-e.kr 2024-08-06
hostname limsjo.p-e.kr 2024-08-06
hostname main.winters.r-e.kr 2024-08-06
hostname netup.p-e.kr 2024-08-06
hostname ol.neqapa.p-e.kr 2024-08-06
hostname www.dcc.mil.kr 2024-08-06