가상화폐 모네로(XMR) 채굴기능의 한국 맞춤형 표적공격 증가
2018-01-15 • ESTSecurity • Increase in targeted attacks targeting Korea for virtual currency Monero (XMR) mining function •
ESRC reports that the operators behind Venus Locker shifted from ransomware activity seen in Korea since late 2016 to distributing malware that secretly mines Monero. The campaign used fluent Korean spear-phishing emails, including lures sent to nurse recruitment contact addresses exposed on Korean medical facility websites. Attachments contained disguised LNK shortcuts and hidden executable malware; the shortcuts masqueraded as image or document files but launched the embedded EXE. After execution, the malware checked for Sandboxie, VMware, and VirtualBox, changed registry settings to disable tools such as CMD, Registry Tools, Task Manager, and UAC, and injected Monero mining code into a legitimate process. The activity is operationally relevant because it shows a Korea-tailored threat actor reusing Venus Locker-style delivery tradecraft while changing the payload objective from extortion to covert cryptocurrency mining.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2018-01-15 | 2018-01-18 | |
| DOMAIN | xmr.pool.minergate.com | 2018-01-15 | 2018-01-18 |