全球加密货币公司的梦魇:揭秘APT组织“危险密码”

2020-01-08 Qianxin The nightmare of global cryptocurrency companies: revealing the "dangerous password" of APT organizations

https://www.secrss.com/articles/16505

Thumbnail for 全球加密货币公司的梦魇:揭秘APT组织“危险密码”

ThreatBook reported a cluster it named DangerousPassword after finding compressed trojan packages built around cryptocurrency-themed lures such as monthly business reports, job descriptions, project risk briefs, and salary guidance. The activity targeted cryptocurrency companies and used phishing emails to deliver archive files containing encrypted Office decoys plus malicious LNK files disguised as password text files. When opened, the LNK chain retrieved VBScript through bit.ly redirects and attacker infrastructure, displayed the decoy password to the victim, established startup persistence, checked for Chinese antivirus processes, and sent host and process data to C2. Reported infrastructure included 41.85.145.164:8080, showprice.xyz, start.showprice.xyz, drivegoogle.publicvm.com, and more than 100 lookalike domains impersonating Google, Microsoft, Amazon, and related services. The campaign matters because it shows a focused, multilingual social-engineering operation against cryptocurrency businesses with backdoor execution, reconnaissance, persistence, and potential follow-on remote-control tooling.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN docs.goglesheet.com 2020-01-08 2022-01-13
DOMAIN drivegoogle.publicvm.com 2019-07-09 2021-05-24
IPv4 41.85.145.164 2020-01-08 2021-01-28
HASH a50ec2f42bec1c43e952de2728de021… 2020-01-08 2020-08-18
DOMAIN download.showprice.xyz 2019-07-09 2020-08-18
DOMAIN msupdate.publicvm.com 2020-01-08 2020-06-24
DOMAIN start.showprice.xyz 2019-07-09 2020-05-06
URL http://download.showprice.xyz:8… 2020-01-08 2020-01-08
URL http://start.showprice.xyz:8080… 2020-01-08 2020-01-08

Related Reports

« Back