개발중인 북한 관련 채굴 악성코드
2018-01-09 • Sands Lab • North Korea-related mining malware under development •
A Korean malware analysis of three AlienVault-published samples links a Monero cryptocurrency miner to suspected North Korea-related activity, noting the broader context of Lazarus shifting toward financial targets. The samples appear to be successive builds of the same project, adding functionality from version 1 through version 3 and deploying components under paths such as C:\Windows\Sys64\updater.exe and C:\Windows\Sys64\intelservice.exe. The latest sample launches the miner with parameters pointing to barjuok.ryongnamsan.edu.kp:5615 and a long wallet address believed to be associated with Monero mining. The report matters because it preserves early technical evidence of DPRK-linked cryptocurrency-mining activity, including hashes, file paths, execution behavior, and mining infrastructure defenders can validate.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c599f3ca3417169e4a620b8231f8a97… | 2018-01-09 | 2018-01-09 |
| HASH | 42300b6a09f183ae167d7a11d9c6df2… | 2018-01-09 | 2018-01-09 |
| HASH | 0024e32c0199ded445c0b968601f21c… | 2018-01-09 | 2018-01-09 |
| DOMAIN | barjuok.ryongnamsan.edu | 2018-01-08 | 2018-01-09 |