疑似Kimsuky(APT-Q-2)以军工招聘为饵攻击欧洲
2024-06-20 • Qianxin • Suspected Kimsuky (APT-Q-2) Uses Military Recruitment Lures Against Europe •
QiAnXin reports a suspected Kimsuky, or APT-Q-2, campaign using fake General Dynamics and Lockheed Martin recruitment lures for defense jobs in Germany to target European military industry personnel. The activity used JSE, C++ and Go droppers to place a DLL payload under ProgramData or fetch it from attacker infrastructure, then execute it with regsvr32. The malware persisted through a CacheDB service when elevated or an HKCU Run key otherwise, stored configuration in NTFS alternate data streams or decrypted it from the .data section, and used RC4 encrypted HTTP POST C2 traffic. QiAnXin cites code similarity, Korean language artifacts, the username niki, and related r-e.kr and o-r.kr infrastructure as reasons the activity is likely connected to Kimsuky, while noting the fake recruitment theme also resembles Lazarus tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8346d90508b5d41d151b7098c7a3e868 | 2024-06-07 | 2025-06-09 |
| HASH | 537806c02659a12c5b21efa51b2322c1 | 2024-06-07 | 2025-06-09 |
| DOMAIN | download.uberlingen.com | 2024-06-07 | 2025-06-09 |
| HASH | aa8936431f7bc0fabb0b9efb6ea153f9 | 2024-06-19 | 2025-05-30 |
| HASH | 73d2899aade924476e58addf26254c2e | 2024-06-19 | 2025-05-24 |
| DOMAIN | online.viewers.r-e.kr | 2024-06-07 | 2024-08-24 |
| DOMAIN | share.dihl-defence.o-r.kr | 2024-06-07 | 2024-08-24 |
| HASH | 3d4a42d00e7b6947d52d03feac236423 | 2024-06-20 | 2024-06-20 |
| HASH | 7221403834a6761696060f1aa22da0fb | 2024-06-20 | 2024-06-20 |
| URL | http://download-attachments.moo… | 2024-06-20 | 2024-06-20 |
| URL | http://apphelloworld.crabdance.… | 2024-06-20 | 2024-06-20 |
| DOMAIN | paypal.uberlingen.com | 2024-06-20 | 2024-06-20 |
| DOMAIN | apphelloworld.crabdance.com | 2024-06-20 | 2024-06-20 |
| HASH | 27d4ff7439694041ef86233c2b804e1f | 2024-06-19 | 2024-06-20 |
| HASH | 8d948bb863ea38ecb46b7e78d1b1abfa | 2024-06-19 | 2024-06-20 |
| URL | http://imagedownload.ignorelist… | 2024-06-19 | 2024-06-20 |
| URL | http://en.uberlingen.com/index.… | 2024-06-19 | 2024-06-20 |
| URL | http://playboys.chickenkiller.c… | 2024-06-19 | 2024-06-20 |
| DOMAIN | imagedownload.ignorelist.com | 2024-06-19 | 2024-06-20 |
| DOMAIN | download-attachments.mooo.com | 2024-06-19 | 2024-06-20 |
| DOMAIN | en.uberlingen.com | 2024-06-19 | 2024-06-20 |
| DOMAIN | playboys.chickenkiller.com | 2024-06-19 | 2024-06-20 |
| IPv4 | 67.217.62.219 | 2024-06-19 | 2024-06-20 |
| URL | http://download.uberlingen.com/… | 2024-06-07 | 2024-06-20 |
| DOMAIN | share-defence.uberlingen.com | 2024-06-07 | 2024-06-20 |
| IPv4 | 94.131.120.80 | 2024-06-07 | 2024-06-20 |