국내 자산 관리 솔루션을 악용하여 공격 중인 Andariel 그룹 (MeshAgent)

2024-03-11 Ahnlab Andariel Group (MeshAgent) is attacking by abusing domestic asset management solutions

https://asec.ahnlab.com/ko/62771/

Thumbnail for 국내 자산 관리 솔루션을 악용하여 공격 중인 Andariel 그룹 (MeshAgent)

AhnLab ASEC reports that Andariel has continued attacks against South Korean companies by abusing domestic asset-management solutions to deploy malware. The campaign uses AndarLoader and ModeLoader, with this case adding MeshAgent as a newly observed remote-management tool in Andariel activity. The source describes ModeLoader launched through mshta, AndarLoader installed as SVPNClientW.exe, credential theft with Mimikatz, security log clearing through wevtutil, and keylogging plus clipboard logging to a public user path. Representative infrastructure includes AndarLoader domains such as privacy.hopto.org and privatemake.bounceme.net, a MeshAgent IP, and multiple ModeLoader URLs under kro.kr and o-r.kr domains.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN privatemake.bounceme.net 2023-08-22 2024-07-25
HASH 4f1b1124e34894398aa423200a8ab894 2024-03-11 2024-03-19
HASH 29efd64dd3c7fe1e2b022b7ad73a1ba5 2024-03-11 2024-03-19
HASH 2c69c4786ce663e58a3cc093c6d5b530 2024-03-11 2024-03-19
HASH a714b928bbc7cd480fed85e379966f95 2024-03-11 2024-03-19
URL http://www.ipservice.kro.kr/mod… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/modeRea… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/modeWri… 2024-03-11 2024-03-19
URL http://www.ipservice.kro.kr/ind… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/modeVie… 2024-03-11 2024-03-19
URL http://panda.ourhome.o-r.kr/mod… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/view.php 2024-03-11 2024-03-19
URL http://www.ipservice.kro.kr/vie… 2024-03-11 2024-03-19
URL http://panda.ourhome.o-r.kr/mod… 2024-03-11 2024-03-19
URL http://panda.ourhome.o-r.kr/vie… 2024-03-11 2024-03-19
DOMAIN privacy.hopto.org 2024-03-11 2024-03-19
DOMAIN panda.ourhome.o-r.kr 2024-03-11 2024-03-19
IPv4 84.38.129.21 2024-03-11 2024-03-19

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back