Caution Against Watering Hole Attack and Malicious File Distribution Disguised as Unification Education Support Application

March 11, 2025, 4:53 p.m.

Description

A watering hole attack targeting unification education program applicants has been discovered. The attackers uploaded malicious HWP document files to a notice board for an educational program. When opened, the file executes hidden malicious code through OLE objects. The malware creates persistence using scheduled tasks, downloads additional payloads, and communicates with a command and control server. Based on the techniques used, the attack is attributed to the North Korean Kimsuky group. Users are advised to exercise caution when downloading application forms from such websites.

Date

  • Created: March 11, 2025, 2:21 p.m.
  • Published: March 11, 2025, 2:21 p.m.
  • Modified: March 11, 2025, 4:53 p.m.

Attack Patterns

  • Kimsuky
  • T1059.005
  • T1059.003
  • T1571
  • T1547.001
  • T1204.002
  • T1105

Additional Informations

  • Education
  • Government