PHISHING MAIL

Continuously Changing Malicious Word Macro Being Distributed – Trend of TA551 (2)

The ASEC analysis team is back to continuously introduce DOC macro documents used by the TA551 group in attacks. The operation flow of macro documents hasn’t changed since its introduction in July. However, we have confirmed that in the most recent case, BazarLoader was distributed at the last step after the macro was run. First, to quote BazarLoader analysis report published in May by AhnLab: Excerpt from ATIP – BazarLoader Analysis Report ‘Abstract’ BazarLoader is a malware that downloads and…

Phishing Site Targeting Domestic E-mail Service Users (Part 2)

The ASEC analysis team has been sharing information about various phishing e-mails in the ASEC blog. This time, the team aims to inform users about another discovered phishing site that targets domestic e-mail service users to distribute malware. The recently confirmed phishing site targets Naver Mail (mail.naver), Daum Mail (mail2.daum), and hiworks users to collect their information such as IDs, passwords, and user IPs. It then sends the information to the attacker’s e-mail. The top-level domain hxxp://za***if***i**pl*ce[.]com/ takes the form…