다양한 원격 제어 도구들을 악용하는 공격자들

2022-10-11 Ahnlab Attackers exploiting various remote control tools

https://asec.ahnlab.com/ko/39761/

Thumbnail for 다양한 원격 제어 도구들을 악용하는 공격자들

AhnLab reviews how attackers abuse legitimate remote administration tools and malicious RATs to take control of infected systems. The report distinguishes backdoors, remote shells, Remote Access Trojans, and normal tools such as AnyDesk and TeamViewer that can be misused after intrusion. It notes that remote-control capability is often an intermediate stage in larger enterprise attacks, enabling lateral movement, information theft, and later ransomware deployment. Examples include commercial or leaked RAT families such as Remcos, AveMaria, BitRAT, RedLine, and NanoCore, alongside legitimate administration software used to blend into victim environments.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1aeb95215a633400d90ad8cbca9bc300 2022-10-11 2022-10-11
HASH fe1bb6811f5c808414c4a357031c2718 2022-10-11 2022-10-11
URL http://bbq.zzhreceive.top/tmate 2022-10-11 2022-10-11
DOMAIN bbq.zzhreceive.top 2022-10-11 2022-10-11
IPv4 58.180.56.28 2022-10-11 2022-10-11
IPv4 106.250.168.50 2022-10-11 2022-10-11
IPv4 119.201.213.146 2022-10-11 2022-10-11
IPv4 183.111.148.147 2022-10-11 2022-10-11

Related Reports

« Back