疑似APT-C-55(Kimsuky)组织利用商业软件Web Browser Password Viewer进行攻击
2021-11-19 • Qihoo360 • Suspected APT-C-55 (Kimsuky) organization uses commercial software Web Browser Password Viewer to carry out attacks •
360 Advanced Threat Research Institute reports suspected APT-C-55/Kimsuky testing malware that repurposes the commercial Web Browser Password Viewer tool to collect browser credentials. The captured sample differs from recent Hancom-themed Kimsuky payloads but still decrypts and decompresses a second stage with RC4 and zlib, injects it into svchost.exe, and checks for an AhnLab V3-related window identifier before hiding it. The malware gathers network, system, process, and file information under the user’s Roaming information directory, while the modified password-viewer component writes suspected browser-password output to aaweb.txt. The researchers note the sample appears incomplete because it lacks persistence and observed upload behavior, but they assess it shows Kimsuky continuing to test commercial-tool modifications for future South Korea-focused operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 56df55ef50e9b9c891437c7148a0764a | 2021-11-19 | 2022-08-30 |
| HASH | 6ae81464fa07cbe9ff288b05f3aefe50 | 2021-11-19 | 2021-11-19 |