疑似Kimsuky(APT-Q-2)以军工招聘为饵攻击欧洲

2024-06-20 Qianxin Suspected Kimsuky (APT-Q-2) Uses Military Recruitment Lures Against Europe

https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247510817&idx=1&sn=733782ef0505c107304c149a763c1ce2

Thumbnail for 疑似Kimsuky(APT-Q-2)以军工招聘为饵攻击欧洲

QiAnXin reports a suspected Kimsuky, or APT-Q-2, campaign using fake General Dynamics and Lockheed Martin recruitment lures for defense jobs in Germany to target European military industry personnel. The activity used JSE, C++ and Go droppers to place a DLL payload under ProgramData or fetch it from attacker infrastructure, then execute it with regsvr32. The malware persisted through a CacheDB service when elevated or an HKCU Run key otherwise, stored configuration in NTFS alternate data streams or decrypted it from the .data section, and used RC4 encrypted HTTP POST C2 traffic. QiAnXin cites code similarity, Korean language artifacts, the username niki, and related r-e.kr and o-r.kr infrastructure as reasons the activity is likely connected to Kimsuky, while noting the fake recruitment theme also resembles Lazarus tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8346d90508b5d41d151b7098c7a3e868 2024-06-07 2025-06-09
HASH 537806c02659a12c5b21efa51b2322c1 2024-06-07 2025-06-09
DOMAIN download.uberlingen.com 2024-06-07 2025-06-09
HASH aa8936431f7bc0fabb0b9efb6ea153f9 2024-06-19 2025-05-30
HASH 73d2899aade924476e58addf26254c2e 2024-06-19 2025-05-24
DOMAIN online.viewers.r-e.kr 2024-06-07 2024-08-24
DOMAIN share.dihl-defence.o-r.kr 2024-06-07 2024-08-24
HASH 3d4a42d00e7b6947d52d03feac236423 2024-06-20 2024-06-20
HASH 7221403834a6761696060f1aa22da0fb 2024-06-20 2024-06-20
URL http://download-attachments.moo… 2024-06-20 2024-06-20
URL http://apphelloworld.crabdance.… 2024-06-20 2024-06-20
DOMAIN paypal.uberlingen.com 2024-06-20 2024-06-20
DOMAIN apphelloworld.crabdance.com 2024-06-20 2024-06-20
HASH 27d4ff7439694041ef86233c2b804e1f 2024-06-19 2024-06-20
HASH 8d948bb863ea38ecb46b7e78d1b1abfa 2024-06-19 2024-06-20
URL http://imagedownload.ignorelist… 2024-06-19 2024-06-20
URL http://en.uberlingen.com/index.… 2024-06-19 2024-06-20
URL http://playboys.chickenkiller.c… 2024-06-19 2024-06-20
DOMAIN imagedownload.ignorelist.com 2024-06-19 2024-06-20
DOMAIN download-attachments.mooo.com 2024-06-19 2024-06-20
DOMAIN en.uberlingen.com 2024-06-19 2024-06-20
DOMAIN playboys.chickenkiller.com 2024-06-19 2024-06-20
IPv4 67.217.62.219 2024-06-19 2024-06-20
URL http://download.uberlingen.com/… 2024-06-07 2024-06-20
DOMAIN share-defence.uberlingen.com 2024-06-07 2024-06-20
IPv4 94.131.120.80 2024-06-07 2024-06-20

Related Actors

Related Reports

« Back