메시에이전트 C2 탐지: 잠재적 악성코드 공격을 예방하는 방법

2024-04-09 Criminal IP Search Query: tag: “c2_meshagent”

https://blog.criminalip.io/ko/2024/04/09/%eb%a9%94%ec%8b%9c%ec%97%90%ec%9d%b4%ec%a0%84%ed%8a%b8/

Thumbnail for 메시에이전트 C2 탐지: 잠재적 악성코드 공격을 예방하는 방법

Andariel activity is reported to involve abuse of MeshAgent as command-and-control tooling against South Korean companies. The source says the operators downloaded a MeshAgent C2 component named fav.ico from an external source and used lateral-movement activity to deploy malware families including AndarLoader and ModeLoader. Because MeshAgent is a remote administration tool with command execution, remote desktop, VNC, power, and account-control features, defenders should distinguish legitimate administration from suspicious installation paths, external retrieval, and follow-on loader execution. The archive is useful for detection work around remote-management-tool abuse, DPRK-linked intrusion operations, and Korean enterprise targeting.

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back