鲨鱼的狂欢 — APT-C-55 Kimsuky组织近期BabyShark组件披露
2022-06-07 • Qihoo360 • Shark's Carnival — APT-C-55 Kimsuky organization's recent disclosure of BabyShark components •
360 attributed multiple first-half 2022 BabyShark component attacks to the Kimsuky organization and linked the malware family to espionage against nuclear security, Korean Peninsula security and cryptocurrency-related targets. The described chain uses malicious DLLs to release VBS scripts, request OneDrive API and 1drv.com URLs, decrypt returned data and upload collected user information to ielsems[.]com for target validation. One related component retrieves desktop.tmp from worldinfocontact[.]club, stores execution logic in a registry value and creates a scheduled task that runs sys.vbs every 29 minutes. The report also identifies an iterative BabyShark DLL sharing export functions and PDB path overlap with earlier Kimsuky BabyShark samples, indicating continued tooling development and infrastructure variation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ielsems.com | 2022-05-05 | 2024-05-10 |
| DOMAIN | dm.files.1drv.com | 2022-06-07 | 2023-05-01 |
| DOMAIN | 1drv.com | 2022-06-07 | 2023-05-01 |
| HASH | 7de6969f867aada10c175e9d4328942e | 2022-06-07 | 2022-06-07 |
| HASH | 3b11456f184a0d263b7f56cb92667b0e | 2022-06-07 | 2022-06-07 |
| HASH | 4bb1827e37223b674ab7270f7b7bbb4d | 2022-06-07 | 2022-06-07 |
| URL | https://api.onedrive.com/v1.0/d… | 2022-06-07 | 2022-06-07 |
| URL | https://qizzhq.dm.files.1drv.co… | 2022-06-07 | 2022-06-07 |
| URL | https://ielsems.com/cic/macro.p… | 2022-06-07 | 2022-06-07 |
| DOMAIN | qizzhq.dm.files.1drv.com | 2022-06-07 | 2022-06-07 |