국내 기업 대상 공격에 사용 중인 Xctdoor 악성코드 (Andariel)

2024-06-24 Ahnlab Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

https://asec.ahnlab.com/ko/67034/

Thumbnail for 국내 기업 대상 공격에 사용 중인 Xctdoor 악성코드 (Andariel)

ASEC observed attacks against South Korean defense and manufacturing organizations involving Xctdoor malware and activity assessed as similar to earlier Andariel use of compromised ERP update mechanisms. In the 2024 cases, attackers appear to have abused a domestic ERP update server or vulnerable web servers to deploy XcLoader and Xctdoor, echoing a 2017 Andariel pattern that inserted malicious routines into ClientUpdater.exe to deliver HotCroissant. Xctdoor is described as a Go-based DLL backdoor launched through Regsvr32.exe, copied into an Edge-related local path, persisted with a MicrosoftEdge.lnk shortcut, and injected into processes such as explorer.exe or taskhost variants. Its capabilities include sending host and user information to HTTP C2, executing attacker commands, capturing screenshots, keylogging, logging clipboard data, and collecting drive information, with packet encryption using mt19937 and Base64. The excerpt also notes web-server compromise, probable webshell command execution, and Ngrok logs, making the activity important for tracking DPRK-linked enterprise intrusion and internal propagation tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9bbde4484821335d98b41b44f93276e8 2024-06-24 2024-07-01
HASH 235e02eba12286e74e886b6c99e46fb7 2024-06-24 2024-07-01
HASH f24627f46ec64cae7a6fa9ee312c43d7 2024-06-24 2024-07-01
HASH 41d5d25de0ca0fdc54c24c484f9f8f55 2024-06-24 2024-07-01
HASH 2e325935b2d1d0a82e63ff2876482956 2024-06-24 2024-07-01
HASH 9a580aaaa3e79b6f19a2c70e89b016e3 2024-06-24 2024-07-01
HASH 396bee51c7485c3a0d3b044a9ceb6487 2024-06-24 2024-07-01
HASH 375f1cc32b6493662a78720c7d905bc3 2024-06-24 2024-07-01
HASH 6928fab25ac1255fbd8d6c1046653919 2024-06-24 2024-07-01
HASH ab8675b4943bc25a51da66565cfc8ac8 2024-06-24 2024-07-01
HASH b96b98dede8a64373b539f94042bdb41 2024-06-24 2024-07-01
HASH a42ae44761ce3294ce0775fe384d97b6 2024-06-24 2024-07-01
HASH d787a33d76552019becfef0a4af78a11 2024-06-24 2024-07-01
HASH d938201644aac3421df7a3128aa88a53 2024-06-24 2024-07-01
HASH e554b1be8bab11e979c75e2c2453bc6a 2024-06-24 2024-07-01
HASH 54d5be3a4eb0e31c0ba7cb88f0a8e720 2024-06-24 2024-07-01
HASH ad96a8f22faab8b9c361cfccc381cd28 2024-06-24 2024-07-01
HASH 11465d02b0d7231730f3c4202b0400b8 2024-06-24 2024-07-01
HASH d852c3d06ef63ea6c6a21b0d1cdf14d4 2024-06-24 2024-07-01
HASH b43a7dcfe53a981831ae763a9a5450fd 2024-06-24 2024-07-01
HASH 4f5e5a392b8a3e0cb32320ed1e8d0604 2024-06-24 2024-07-01
HASH 09a5069c9cc87af39bbb6356af2c1a36 2024-06-24 2024-07-01
URL http://www.jikji.pe.kr/xe/files… 2024-06-24 2024-07-01
URL http://beebeep.info/index.php 2024-06-24 2024-07-01
DOMAIN beebeep.info 2024-06-24 2024-07-01
IPv4 195.50.242.110 2024-06-24 2024-07-01

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

2024-07-19 • 48% Match
#Trend #Andariel #Kimsuky #MoonstoneSleet #Lazarus #T1082 #T1059.003 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1046 #T1112 #T1115 #T1083 #T1497 #T1056.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1071 #T1124 #T1222 #T1552 #T1057 #T1583.003 #T1518.001 #T1547.001 #T1053.005 #T1539 #T1608.005 #T1583.001 #T1059.001 #T1053 #T1552.001 #T1566 #T1059 #T1003 #T1497.001 #T1102.001 #T1574.002 #T1562.001 #T1490 #T1486 #T1129 #T1133 #T1571 #T1548 #T1190 #T1203 #T1564.001 #T1087 #T1562.004 #T1218.011 #T1070.006 #T1547 #T1068 #T1614 #T1573 #T1095 #T1562 #T1070 #T1047 #T1056 #T1176 #T1010 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1202 #T1087.002 #T1021.004 #T1222.001 #T1518 #T1564.003 #T1505.003 #T1069.002 #T1564 #T1595.002 #T1027.005 #T1070.001 #T1056.004 #T1584
Shares tag: Andariel • Published within a month
« Back