推陈出新!Kimsuky组织最新远控组件攻击场景复现
2024-03-25 • Aliyun • Cyber threat report on Kimsuky •
The analysis reconstructs a Kimsuky PowerShell backdoor and its control scenario after a sample and controller interface were shared publicly. The backdoor initiates socket-based communication to a configured address, uses RC4 encryption, and derives a unique key value from host MAC and IP data before command exchange. Its 12 remote-control functions include drive and directory listing, file deletion, program execution, ZIP creation, directory creation, file upload, restart/close behavior, and file or directory exfiltration by POSTing base64-encoded content to a C2 URL ending in /show.php. The author also derives network detection opportunities from the protocol, including a fixed first-stage byte pattern, heartbeat packets of 00, and a command structure based on payload length followed by payload data.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5fd47df267932964a5b9340e55416ba1 | 2024-03-25 | 2024-03-25 |
| HASH | 3546443437444632363739333239363… | 2024-03-25 | 2024-03-25 |