Email accounts on various public mail services are used to control bots and serve as drop zones.
We have identified the following mail services that have been abused: mail.bg, hotmail.com, gmail.com, india.com, gmx.com, mail.com, zoho.com, indiatimes.com, 8panther.com
Academia/Research
Government entities
Private companies
Strings left by malware author in the compile paths of the malicious samples' bodies suggest the attack has Korean origins. Also we have been able to define the IP addresses from which attackers visited their email accounts to control the bots. All those IP addresses turned out to be Chinese areas bordering North Korea. Internet Providers from these areas are believed to provide Internet into North Korea. All this, as well as the fact that the targets are of specific interest to the North Korean government, could suggest that North Korea might be behind this threat actor.
The blog post and research paper are available atSecurelist.com