국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)
2024-03-19 • Ahnlab • Malicious code disguised as installation files of domestic public institutions (Kimsuky group) •
AhnLab reports that Kimsuky distributed a dropper disguised as a Korean public institution installer, signed with a valid domestic certificate, to deploy the Endoor backdoor. The dropper creates src.rar and unrar.exe, extracts the payload with the password 1q2w3e4r, and runs Endoor with an install argument so it copies itself to %USERPROFILE%\svchost.exe and registers a Windows Backup scheduled task. Follow-on activity included suspected Endoor updates, Mimikatz execution with sekurlsa::logonpasswords, screenshot theft, and use of Endoor and Nikidoor infrastructure including ngrok-free[.]app and minish.wiki[.]gd. The report links the activity to Kimsuky's continued use of signed malware, backdoors, and credential theft against Korean targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7034268d1c52539ea0cd48fd33ae43c4 | 2024-03-19 | 2024-03-26 |
| HASH | f03618281092b02589bca833f674e8a0 | 2024-03-19 | 2024-03-26 |
| HASH | 7beaf468765b2f1f346d43115c894d4b | 2024-03-19 | 2024-03-26 |
| HASH | b74efd8470206a20175d723c14c2e872 | 2024-03-19 | 2024-03-26 |
| HASH | b8ffb0b5bc3c66b7f1b0ec5cc4aadafc | 2024-03-19 | 2024-03-26 |
| URL | http://minish.wiki.gd/index.php | 2024-03-19 | 2024-03-26 |
| URL | http://minish.wiki.gd/eng.db | 2024-03-19 | 2024-03-26 |
| URL | http://minish.wiki.gd/upload.php | 2024-03-19 | 2024-03-26 |
| URL | https://real-joey-nicely.ngrok-… | 2024-03-19 | 2024-03-26 |
| URL | http://minish.wiki.gd/c.pdf | 2024-03-19 | 2024-03-26 |
| URL | https://fitting-discrete-lemur.… | 2024-03-19 | 2024-03-26 |
| DOMAIN | minish.wiki.gd | 2024-03-19 | 2024-03-26 |
| IPv4 | 210.16.120.210 | 2024-03-19 | 2024-03-26 |