다양한 주제를 이용하여 CHM 악성코드를 유포 중인 Kimsuky

2023-06-16 Ahnlab Kimsuky is spreading CHM malware using various topics.

https://asec.ahnlab.com/ko/53426/

Thumbnail for 다양한 주제를 이용하여 CHM 악성코드를 유포 중인 Kimsuky

AhnLab describes a May 2023 Kimsuky campaign that increasingly used CHM help files rather than ordinary document lures, with themes tailored to Korean targets such as tax filings, financial transactions, cryptocurrency records, contracts, certificates, and order sheets. The CHM files displayed normal-looking help windows while embedded script commands wrote encoded data under the user Links folder, decoded VBS/BAT components with certutil, registered persistence in the Run key, and launched a runner chain. The downloaded BAT and CAB components collected user information, sent it with the computer name to hxxp://vndjgheruewy1[.]com/uun06/uwpp.php, and repeatedly checked for target-specific additional payloads named with the infected PC name. The activity shows Kimsuky using stolen personal information and selective follow-on malware delivery to make CHM-based APT attacks more targeted.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ae6fdb8945991b587ab790c2121345ce 2023-06-16 2023-06-21
HASH 075160d6c8d82b96d1ae7893761695a6 2023-06-16 2023-06-21
HASH d62dcb76fa0fb4b725ea9c8643874ae7 2023-06-16 2023-06-21
HASH 98764ae00cee9f2cc87530601c159387 2023-06-16 2023-06-21
HASH 9861999409cdbc1f7c4c1079d348697c 2023-06-16 2023-06-21
HASH ef58a1326b98feccc90c4d37a8ce2fe2 2023-06-16 2023-06-21
HASH b5a873ee6b839cbd03789115fc3ae944 2023-06-16 2023-06-21
HASH e5b0430290dc71193b7ea2fc829a9910 2023-06-16 2023-06-21
HASH e9e56ee78e019e09d5dbe0bb373adf09 2023-06-16 2023-06-21
HASH 7c7b8dd6dd4ba7b443e84287671f0e79 2023-06-16 2023-06-21
URL http://vndjgheruewy1.com/tnd/pu… 2023-06-16 2023-06-21
URL http://vndjgheruewy1.com/jun06/… 2023-06-16 2023-06-21
URL http://vndjgheruewy1.com/tnd/qu… 2023-06-16 2023-06-21
URL http://vndjgheruewy1.com/uun06/… 2023-06-16 2023-06-21
DOMAIN vndjgheruewy1.com 2023-06-16 2023-06-21

Related Actors

Related Reports

« Back