疑似Kimsuky针对韩国军工行业的攻击
2021-07-08 • Qihoo360 • Suspected Kimsuky attacks targeting South Korea's military industry •
360 reports a suspected Kimsuky operation aimed at South Korean military or defense-related targets, using a PE sample disguised with a Microsoft-style icon and a Korean HWP procurement-plan lure. The first-stage malware displayed the decoy document, created a version-like mutex, invoked mshta.exe against vpn.atooi.ga, and then self-deleted with a BAT script. Related DLL samples used similar mutex naming, decrypted embedded shellcode, and injected it into rundll32.exe, where the shellcode attempted to contact 27.102.127.240 for additional code. The analysis links the backdoor's string/API decryption approach to historical Kimsuky tooling while retaining cautious attribution as suspected Kimsuky activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d4da4660836d61db95dd91936e7cfa4a | 2021-07-08 | 2021-07-08 |
| HASH | 7f4624a8eb740653e2242993ee9e0997 | 2021-07-08 | 2021-07-08 |
| URL | http://vpn.atooi.ga/?query=5 | 2021-07-08 | 2021-07-08 |
| DOMAIN | vpn.atooi.ga | 2021-07-08 | 2021-07-08 |
| IPv4 | 27.102.127.240 | 2021-07-08 | 2021-07-08 |