국내 자산 관리 솔루션을 악용하여 공격 중인 Andariel 그룹 (MeshAgent)
2024-03-11 • Ahnlab • Andariel Group (MeshAgent) is attacking by abusing domestic asset management solutions •
AhnLab ASEC reports that Andariel has continued attacks against South Korean companies by abusing domestic asset-management solutions to deploy malware. The campaign uses AndarLoader and ModeLoader, with this case adding MeshAgent as a newly observed remote-management tool in Andariel activity. The source describes ModeLoader launched through mshta, AndarLoader installed as SVPNClientW.exe, credential theft with Mimikatz, security log clearing through wevtutil, and keylogging plus clipboard logging to a public user path. Representative infrastructure includes AndarLoader domains such as privacy.hopto.org and privatemake.bounceme.net, a MeshAgent IP, and multiple ModeLoader URLs under kro.kr and o-r.kr domains.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | privatemake.bounceme.net | 2023-08-22 | 2024-07-25 |
| HASH | 4f1b1124e34894398aa423200a8ab894 | 2024-03-11 | 2024-03-19 |
| HASH | 29efd64dd3c7fe1e2b022b7ad73a1ba5 | 2024-03-11 | 2024-03-19 |
| HASH | 2c69c4786ce663e58a3cc093c6d5b530 | 2024-03-11 | 2024-03-19 |
| HASH | a714b928bbc7cd480fed85e379966f95 | 2024-03-11 | 2024-03-19 |
| URL | http://www.ipservice.kro.kr/mod… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/modeRea… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/modeWri… | 2024-03-11 | 2024-03-19 |
| URL | http://www.ipservice.kro.kr/ind… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/modeVie… | 2024-03-11 | 2024-03-19 |
| URL | http://panda.ourhome.o-r.kr/mod… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/view.php | 2024-03-11 | 2024-03-19 |
| URL | http://www.ipservice.kro.kr/vie… | 2024-03-11 | 2024-03-19 |
| URL | http://panda.ourhome.o-r.kr/mod… | 2024-03-11 | 2024-03-19 |
| URL | http://panda.ourhome.o-r.kr/vie… | 2024-03-11 | 2024-03-19 |
| DOMAIN | privacy.hopto.org | 2024-03-11 | 2024-03-19 |
| DOMAIN | panda.ourhome.o-r.kr | 2024-03-11 | 2024-03-19 |
| IPv4 | 84.38.129.21 | 2024-03-11 | 2024-03-19 |