疑似Kimsuky针对韩国军工行业的攻击

2021-07-08 Qihoo360 Suspected Kimsuky attacks targeting South Korea's military industry

https://mp.weixin.qq.com/s/y4TGzrhr2rvVk5EAca91hA

Thumbnail for 疑似Kimsuky针对韩国军工行业的攻击

360 reports a suspected Kimsuky operation aimed at South Korean military or defense-related targets, using a PE sample disguised with a Microsoft-style icon and a Korean HWP procurement-plan lure. The first-stage malware displayed the decoy document, created a version-like mutex, invoked mshta.exe against vpn.atooi.ga, and then self-deleted with a BAT script. Related DLL samples used similar mutex naming, decrypted embedded shellcode, and injected it into rundll32.exe, where the shellcode attempted to contact 27.102.127.240 for additional code. The analysis links the backdoor's string/API decryption approach to historical Kimsuky tooling while retaining cautious attribution as suspected Kimsuky activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d4da4660836d61db95dd91936e7cfa4a 2021-07-08 2021-07-08
HASH 7f4624a8eb740653e2242993ee9e0997 2021-07-08 2021-07-08
URL http://vpn.atooi.ga/?query=5 2021-07-08 2021-07-08
DOMAIN vpn.atooi.ga 2021-07-08 2021-07-08
IPv4 27.102.127.240 2021-07-08 2021-07-08

Related Actors

Related Reports

« Back