국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)

2024-03-19 Ahnlab Malicious code disguised as installation files of domestic public institutions (Kimsuky group)

https://asec.ahnlab.com/ko/62117/

Thumbnail for 국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)

AhnLab reports that Kimsuky distributed a dropper disguised as a Korean public institution installer, signed with a valid domestic certificate, to deploy the Endoor backdoor. The dropper creates src.rar and unrar.exe, extracts the payload with the password 1q2w3e4r, and runs Endoor with an install argument so it copies itself to %USERPROFILE%\svchost.exe and registers a Windows Backup scheduled task. Follow-on activity included suspected Endoor updates, Mimikatz execution with sekurlsa::logonpasswords, screenshot theft, and use of Endoor and Nikidoor infrastructure including ngrok-free[.]app and minish.wiki[.]gd. The report links the activity to Kimsuky's continued use of signed malware, backdoors, and credential theft against Korean targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7034268d1c52539ea0cd48fd33ae43c4 2024-03-19 2024-03-26
HASH f03618281092b02589bca833f674e8a0 2024-03-19 2024-03-26
HASH 7beaf468765b2f1f346d43115c894d4b 2024-03-19 2024-03-26
HASH b74efd8470206a20175d723c14c2e872 2024-03-19 2024-03-26
HASH b8ffb0b5bc3c66b7f1b0ec5cc4aadafc 2024-03-19 2024-03-26
URL http://minish.wiki.gd/index.php 2024-03-19 2024-03-26
URL http://minish.wiki.gd/eng.db 2024-03-19 2024-03-26
URL http://minish.wiki.gd/upload.php 2024-03-19 2024-03-26
URL https://real-joey-nicely.ngrok-… 2024-03-19 2024-03-26
URL http://minish.wiki.gd/c.pdf 2024-03-19 2024-03-26
URL https://fitting-discrete-lemur.… 2024-03-19 2024-03-26
DOMAIN minish.wiki.gd 2024-03-19 2024-03-26
IPv4 210.16.120.210 2024-03-19 2024-03-26

Related Actors

Related Reports

« Back