鲨鱼的狂欢 — APT-C-55 Kimsuky组织近期BabyShark组件披露

2022-06-07 Qihoo360 Shark's Carnival — APT-C-55 Kimsuky organization's recent disclosure of BabyShark components

https://mp.weixin.qq.com/s/ZV8AOTd7YGUgCTTTZtTktQ

Thumbnail for 鲨鱼的狂欢 — APT-C-55 Kimsuky组织近期BabyShark组件披露

360 attributed multiple first-half 2022 BabyShark component attacks to the Kimsuky organization and linked the malware family to espionage against nuclear security, Korean Peninsula security and cryptocurrency-related targets. The described chain uses malicious DLLs to release VBS scripts, request OneDrive API and 1drv.com URLs, decrypt returned data and upload collected user information to ielsems[.]com for target validation. One related component retrieves desktop.tmp from worldinfocontact[.]club, stores execution logic in a registry value and creates a scheduled task that runs sys.vbs every 29 minutes. The report also identifies an iterative BabyShark DLL sharing export functions and PDB path overlap with earlier Kimsuky BabyShark samples, indicating continued tooling development and infrastructure variation.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ielsems.com 2022-05-05 2024-05-10
DOMAIN dm.files.1drv.com 2022-06-07 2023-05-01
DOMAIN 1drv.com 2022-06-07 2023-05-01
HASH 7de6969f867aada10c175e9d4328942e 2022-06-07 2022-06-07
HASH 3b11456f184a0d263b7f56cb92667b0e 2022-06-07 2022-06-07
HASH 4bb1827e37223b674ab7270f7b7bbb4d 2022-06-07 2022-06-07
URL https://api.onedrive.com/v1.0/d… 2022-06-07 2022-06-07
URL https://qizzhq.dm.files.1drv.co… 2022-06-07 2022-06-07
URL https://ielsems.com/cic/macro.p… 2022-06-07 2022-06-07
DOMAIN qizzhq.dm.files.1drv.com 2022-06-07 2022-06-07

Related Actors

Related Reports

« Back