疑似APT-C-55(Kimsuky)组织利用商业软件Web Browser Password Viewer进行攻击

2021-11-19 Qihoo360 Suspected APT-C-55 (Kimsuky) organization uses commercial software Web Browser Password Viewer to carry out attacks

https://mp.weixin.qq.com/s/QDI912ogVKyyKFYdKvBGdQ

Thumbnail for 疑似APT-C-55(Kimsuky)组织利用商业软件Web Browser Password Viewer进行攻击

360 Advanced Threat Research Institute reports suspected APT-C-55/Kimsuky testing malware that repurposes the commercial Web Browser Password Viewer tool to collect browser credentials. The captured sample differs from recent Hancom-themed Kimsuky payloads but still decrypts and decompresses a second stage with RC4 and zlib, injects it into svchost.exe, and checks for an AhnLab V3-related window identifier before hiding it. The malware gathers network, system, process, and file information under the user’s Roaming information directory, while the modified password-viewer component writes suspected browser-password output to aaweb.txt. The researchers note the sample appears incomplete because it lacks persistence and observed upload behavior, but they assess it shows Kimsuky continuing to test commercial-tool modifications for future South Korea-focused operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 56df55ef50e9b9c891437c7148a0764a 2021-11-19 2022-08-30
HASH 6ae81464fa07cbe9ff288b05f3aefe50 2021-11-19 2021-11-19

Related Actors

Related Reports

« Back