推陈出新!Kimsuky组织最新远控组件攻击场景复现

2024-03-25 Aliyun Cyber threat report on Kimsuky

https://xz.aliyun.com/t/14181

Thumbnail for 推陈出新!Kimsuky组织最新远控组件攻击场景复现

The analysis reconstructs a Kimsuky PowerShell backdoor and its control scenario after a sample and controller interface were shared publicly. The backdoor initiates socket-based communication to a configured address, uses RC4 encryption, and derives a unique key value from host MAC and IP data before command exchange. Its 12 remote-control functions include drive and directory listing, file deletion, program execution, ZIP creation, directory creation, file upload, restart/close behavior, and file or directory exfiltration by POSTing base64-encoded content to a C2 URL ending in /show.php. The author also derives network detection opportunities from the protocol, including a fixed first-stage byte pattern, heartbeat packets of 00, and a command structure based on payload length followed by payload data.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5fd47df267932964a5b9340e55416ba1 2024-03-25 2024-03-25
HASH 3546443437444632363739333239363… 2024-03-25 2024-03-25

Related Actors

Related Reports

« Back