韩美大规模联合军演挑衅升级朝方 APT 组织近期攻击活动分析

2023-09-12 Knownsec Large-scale joint military exercises between South Korea and the United States escalate the provocation. Analysis of recent attacks by North Korean APT organizations

https://paper.seebug.org/3030/

Thumbnail for 韩美大规模联合军演挑衅升级朝方 APT 组织近期攻击活动分析

Knownsec 404 researchers observed a sharp rise in North Korean APT activity against South Korean targets during the August 2023 Ulchi Freedom Shield joint exercises. The report says more than 80 samples were captured during the exercises and more than 200 deduplicated samples by early September, with APT37 accounting for most of the activity and LNK or CHM files commonly used as first-stage delivery. It documents APT37 use of oversized LNK packaging and two Chinotto variants, while Konni activity used LNK and CHM lures, VBS and BAT scripts, bitsadmin and certutil, CAB payloads, Run-key persistence, and collection of desktop file lists, IP data, and system information. The authors assess the activity as broad intelligence collection against South Korea, with both APT37 and Konni changing chains and obfuscation to maintain operational stability after public disclosures.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 778e46f8f3641a92d34da68dffc168f… 2023-09-12 2024-08-22
HASH d245f208d2a682f4d2c4464557973bf… 2023-09-12 2024-05-20
HASH dd85c8400fb30e4d02f0159aab3c3db… 2023-09-01 2023-11-24
HASH b3653c1d66f7878c2c5b60506bfe6fb… 2023-09-12 2023-09-13
HASH 9fd5094447ff48e7ec032ced663717c… 2023-09-12 2023-09-13
HASH 6a6f7bdca0423b8702c1803bf5593e2… 2023-09-12 2023-09-13
HASH be568aad2e29b25609358b7793a36eb… 2023-09-12 2023-09-13
HASH f9171a375f765eae7a0babe94acaa08… 2023-09-12 2023-09-13
HASH 440ca9963b73653615de02e44b2ccd1… 2023-09-12 2023-09-13
HASH f4897180b6d70b8134ed0a433af33ae… 2023-09-12 2023-09-13
HASH 87d60ea4650c18a1629892b26e22c97… 2023-09-12 2023-09-13
HASH 151bfb656ce44249960c7aee094884c… 2023-09-12 2023-09-13
HASH cabdc51411d452e30e6fd6786a95752… 2023-09-12 2023-09-13
URL https://chainilnk.site/customer… 2023-09-12 2023-09-13
DOMAIN chainilnk.site 2023-09-12 2023-09-13
HASH b31b89e646de6e9c5cbe21798e0157f… 2023-09-07 2023-09-13
HASH 01e7405ddd5545ffb4a57040acc4b6f… 2023-08-25 2023-09-13
HASH a1f6ae788bf3f9ae17893f3b12d557f… 2023-08-25 2023-09-13
HASH 012063e0b7b4f7f3ce50574797112f9… 2023-08-25 2023-09-13
HASH f5e46e18facc6f8fde6658b96dcd379… 2023-08-25 2023-09-13
HASH 578689cb4b06c4d3f1850e4379c4b31… 2023-08-25 2023-09-13

Related Actors

Related Reports

« Back