개발중인 북한 관련 채굴 악성코드

2018-01-09 Sands Lab North Korea-related mining malware under development

http://story.malwares.com/116

A Korean malware analysis of three AlienVault-published samples links a Monero cryptocurrency miner to suspected North Korea-related activity, noting the broader context of Lazarus shifting toward financial targets. The samples appear to be successive builds of the same project, adding functionality from version 1 through version 3 and deploying components under paths such as C:\Windows\Sys64\updater.exe and C:\Windows\Sys64\intelservice.exe. The latest sample launches the miner with parameters pointing to barjuok.ryongnamsan.edu.kp:5615 and a long wallet address believed to be associated with Monero mining. The report matters because it preserves early technical evidence of DPRK-linked cryptocurrency-mining activity, including hashes, file paths, execution behavior, and mining infrastructure defenders can validate.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c599f3ca3417169e4a620b8231f8a97… 2018-01-09 2018-01-09
HASH 42300b6a09f183ae167d7a11d9c6df2… 2018-01-09 2018-01-09
HASH 0024e32c0199ded445c0b968601f21c… 2018-01-09 2018-01-09
DOMAIN barjuok.ryongnamsan.edu 2018-01-08 2018-01-09

Related Actors

Related Reports

« Back