標的型攻撃グループCryptoMimicの攻撃手法の変化について

2021-02-01 NTTSecurity Changes in the attack methods of the targeted attack group CryptoMimic

https://insight-jp.nttsecurity.com/post/102gpur/cryptomimic

Thumbnail for 標的型攻撃グループCryptoMimicの攻撃手法の変化について

NTT Security Japan reported changes in CryptoMimic activity, a financially motivated targeted attack group also known as Dangerous Password, CageyChameleon, Leery Turtle, or CryptoCore and described as having possible Lazarus links. The group continued targeting financial institutions, especially cryptocurrency-related organizations in Japan and other countries, while updating Cabbage RAT and msoRAT tradecraft. Since around June 2020, observed attacks shifted from VBScript to JScript Cabbage RAT components, delivered through ZIP files containing decoy documents and LNK shortcut files received via email or LinkedIn-linked URLs. The newer dropper used mshta.exe to download and run JScript, opened Google Drive-hosted decoy documents, created startup-folder persistence, and added checks for BitDefender and Symantec products.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 103.31.249.62 2021-01-28 2021-02-01
IPv4 45.61.139.215 2021-01-28 2021-02-01
IPv4 103.130.195.170 2021-01-28 2021-02-01
IPv4 84.201.189.216 2020-11-24 2021-02-01

Related Actors

Related Reports

« Back