Sunday, December 29, 2024
HomeSecurity NewsPhishing Campaign Targeting Companies Associated with Pyeongchang Olympics

Phishing Campaign Targeting Companies Associated with Pyeongchang Olympics

Published on

SIEM as a Service

Security researchers from McAfee spotted a Phishing campaign targeting companies associated with Pyeongchang Olympic 2018.The multi-sport event is to take place in South Korea.

Hackers primarily targetted icehockey@pyeongchang2018.com and several other Korean companies in BCC.And most of them associated in some way to Pyeongchang Olympic.

McAfee Researchers spotted the campaign started on December 22, 2017, and the activity appeared up to December 28, 2017.All the Email sent from IP address 43.249.39.152 in Singapore and the attackers spoofed the Email address to have appeared as info@nctc.go.kr.

Attached is an email was a malicious Microsoft Word document with the original file name 농식품부, 평창 동계올림픽 대비 축산악취 방지대책 관련기관 회의 개최.doc (“Organized by Ministry of Agriculture and Forestry and Pyeongchang Winter Olympics”).
- Advertisement - SIEM as a Service

Attackers embedded malicious documents as a hypertext application (HTA) file and then hide it as an image in the remote server with visual basic macros to launch the decoder script.Researchers said they also wrote custom PowerShell code to decode the hidden image and reveal the implant.

Also Read Real-Time Intelligence Feed to Catch Malicious Phishing Domains SSL Certificate

When the victim opens the document it asks to “enable content” to load the file properly in word, if victim clicks on “enable content” then the malicious document executes PowerShell script which downloads and reads an image file from a remote location and carves out a hidden PowerShell implant script embedded within the image file to execute.

The script is heavily disguised with string-based obfuscation to make the analysis job difficult researchers deobfuscate the control server URLs, the implant establishes a connection to the following site over SSL.

hxxps://www[dot]thlsystems[dot]forfirst[dot]cz:443/components/com_tags/views/login/process[dot]php

Researchers said, based on our analysis, this implant establishes an encrypted channel to the attacker’s server, likely giving the attacker the ability to execute commands on the victim’s machine and to install additional malware.

With the upcoming Olympics, we expect to see an increase in cyber attacks using Olympics-related themes,” the McAfee report concluded.

IoC of attacks – Pyeongchang Olympic

SHA-1

c388b693d10e2b84af52ab2c29eb9328e47c3c16
8ad0a56e3db1e2cd730031bdcae2dbba3f7aba9c

IPs

200.122.181.63

Domains

thlsystems.forfirst.cz
mafra.go.kr.jeojang.ga
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a...

New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers

Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated...

NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern

The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms...

Palo Alto Networks Vulnerability Puts Firewalls at Risk of DoS Attacks

A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

North Korean Hackers Stolen $2.2 Billion From Crypto Platforms In 2024

Cryptocurrency hacking incidents in 2024 surged 21.07% YoY to $2.2 billion, with 303 breaches...

Deloitte Denies Breach, Claims Only Single System Affected

Ransomware group Brain Cipher claimed to have breached Deloitte UK and threatened to publish...

Poison Ivy APT Launches Continuous Cyber Attack on Defense, Gov, Tech & Edu Sectors

Researchers uncovered the resurgence of APT-C-01, also known as the Poison Ivy group, an...