문서 뷰어로 위장한 악성 배치 파일(*.bat) 유포 중(Kimsuky)

2023-06-30 Ahnlab Distributing malicious batch files (*.bat) disguised as document viewers (Kimsuky)

https://asec.ahnlab.com/ko/54952/

Thumbnail for 문서 뷰어로 위장한 악성 배치 파일(*.bat) 유포 중(Kimsuky)

AhnLab reports that malware assessed as Kimsuky activity was distributed as batch files disguised as document viewers, likely via email, with decoy Google Drive/Docs documents about military and Korean unification topics. The BAT file used WMIC to check installed security products and downloaded different scripts from joongang[.]site depending on Kaspersky, Avast, AhnLab V3, or other process matches. Follow-on components replaced Word's Normal.dotm, registered VBS persistence through the registry, startup folder, or a scheduled task, and modified browser/email shortcuts so user launches could execute attacker-controlled commands such as mshta. The scripts also collected host details including battery and process information and sent them to joongang[.]site, while AhnLab listed related BAT/VBS detections and representative infrastructure such as joongang[.]site and namsouth[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN namsouth.com 2023-06-30 2024-02-28
HASH 8536d838dcdd026c57187ec2c3aec0f6 2023-06-30 2023-07-10
HASH 00119ed01689e76cb7f33646693ecd6a 2023-06-30 2023-07-10
HASH 7d79901b01075e29d8505e72d225ff52 2023-06-30 2023-07-10
HASH a7ac7d100184078c2aa5645552794c19 2023-06-30 2023-07-10
URL http://joongang.site/pprb/sec/c… 2023-06-30 2023-07-10
URL http://joongang.site/pprb/sec/c… 2023-06-30 2023-07-10
URL http://namsouth.com/gopprb/OpOp… 2023-06-30 2023-07-10
URL http://joongang.site/docx/ 2023-06-30 2023-07-10
URL https://joongang.site/pprb/sec/… 2023-06-30 2023-07-10
URL http://joongang.site/pprb/sec/c… 2023-06-30 2023-07-10
URL http://joongang.site/pprb/sec/ 2023-06-30 2023-07-10
URL http://joongang.site/pprb/sec/d… 2023-06-30 2023-07-10
URL https://joongang.site/pprb/sec/… 2023-06-30 2023-07-10
URL http://joongang.site/doc/ 2023-06-30 2023-07-10
URL https://joongang.site/pprb/sec/… 2023-06-30 2023-07-10
URL http://staradvertiser.store/sig… 2023-06-30 2023-07-10
URL https://joongang.site/pprb/sec/… 2023-06-30 2023-07-10
URL https://joongang.site/pprb/sec/… 2023-06-30 2023-07-10
DOMAIN staradvertiser.store 2023-06-30 2023-07-10
DOMAIN joongang.site 2023-06-30 2023-07-10

Related Actors

Related Reports

« Back