来自Kimsuky组织的突刺:多种攻击武器针对韩国的定向猎杀

2022-09-14 Qianxin Sting from the Kimsuky organization: Targeted hunting with multiple attack weapons against South Korea

https://www.secrss.com/articles/46887

Thumbnail for 来自Kimsuky组织的突刺:多种攻击武器针对韩国的定向猎杀

Kimsuky targeted South Korean entities during a period of U.S.-South Korea military exercises, using PIF, HWP, DOC and macro-enabled lure files to deliver malware. The activity used PIF executables disguised with PDF icons, Korean DRM-encrypted decoy documents, custom string decryption, XOR/AES/RC4 routines, scheduled tasks and registry Run keys for execution and persistence. Payloads included PebbleDash, AppleSeed-linked tradecraft, VBS downloaders, PowerShell-based host reconnaissance, and a lightweight backdoor loaded through regsvr32 that communicated with C2 infrastructure over HTTP. Reported infrastructure included uppgrede.scienceontheweb.net, office.pushitlive.net, qwert.mine.bz and related URLs, with observed capabilities for host information collection, command execution and result exfiltration. The campaign matters because it shows Kimsuky reusing stolen Korean documents as lures while combining multiple malware families and flexible delivery chains against South Korea-focused targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 12539ac37a81cc2e19338a67d237f833 2022-09-14 2024-03-12
URL http://qwert.mine.bz/index.php 2022-09-14 2024-03-12
DOMAIN qwert.mine.bz 2022-09-14 2024-03-12
IPv4 216.189.154.6 2022-08-25 2024-03-12
DOMAIN uppgrede.scienceontheweb.net 2022-09-14 2023-10-30
HASH a4d58f1bcce687d4ea60a3fe60120d5e 2022-09-14 2022-09-14
HASH 4de19e2c39b1d193e171dc8d804005a4 2022-09-14 2022-09-14
HASH f6628bd40f4cd6cc8405541c269ac901 2022-09-14 2022-09-14
HASH 77b7856144515bb3905df8b3fb210a2e 2022-09-14 2022-09-14
HASH 19ef39e9936b7b46e88d55115dfa9679 2022-09-14 2022-09-14
URL http://uppgrede.scienceontheweb… 2022-09-14 2022-09-14
URL http://uppgrede.scienceontheweb… 2022-09-14 2022-09-14
URL http://uppgrede.scienceontheweb… 2022-09-14 2022-09-14
URL http://office.pushitlive.net/in… 2022-09-14 2022-09-14
URL http://uppgrede.scienceontheweb… 2022-09-14 2022-09-14
URL http://uppgrede.scienceontheweb… 2022-09-14 2022-09-14
DOMAIN office.pushitlive.net 2022-09-14 2022-09-14
URL http://yulsohnyonsei.atwebpages… 2022-08-25 2022-09-14
URL http://yulsohnyonsei.atwewbpage… 2022-08-25 2022-09-14
DOMAIN yulsohnyonsei.atwewbpages.com 2022-08-25 2022-09-14
DOMAIN yulsohnyonsei.atwebpages.com 2022-08-25 2022-09-14
HASH 6083a1af637d9dd2b2a16538a17e1f45 2022-08-23 2022-09-14
HASH ca2917006eb29171c9e5f374e789f53a 2022-08-23 2022-09-14
URL https://driver.googledocs.cloud… 2022-08-23 2022-09-14
DOMAIN driver.googledocs.cloudns.nz 2022-08-23 2022-09-14

Related Actors

Related Reports

« Back