보안 설치 프로그램으로 위장한 북한의 XCTDoor 실행 과정

2026-03-30 Hauri Execution Process of North Korea's XCTDoor Disguised as a Security Installer

https://hauri.co.kr/security/security_view.html?intSeq=86&page=1&keyfield=&key=

Attachments

2026-03-27ììëìë³ê³ìë³ììì¹íëêëì¼ëììíëíìXCTDoorìíê³¼ì.pdf (1 MB)

Thumbnail for 보안 설치 프로그램으로 위장한 북한의 XCTDoor 실행 과정

HAURI analyzed a Korean campaign that disguised malware as a required integrated security installer used for banking and public-sector websites, with the archive mimicking Veraport by using a similar filename and normal-looking installation flow. The infection chain used DLL sideloading through a legitimate Microsoft utility and a hidden malicious credui.dll, then created scripts under public user folders and scheduled tasks named office365 and AdobeUpdate to stage additional payloads. HAURI links the activity to a suspected North Korea-related threat group based on an encrypted string key referencing Songun, while the delivery infrastructure included lengitan[.]info and hesenorm[.]info download paths. The final XCTDoor payload, loaded from Microsoft Edge-like paths as Go DLL components, supports system information collection, monitoring, remote command execution, additional malware download, and control of infected hosts.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f05d11616979d4b3a02024f0ec075b3b 2026-03-30 2026-03-30
HASH 1a77dddae05b6bd96820902b6aee9cc3 2026-03-30 2026-03-30
HASH 97b14304761a2baa620007b2df8d6547 2026-03-30 2026-03-30
HASH c43a146f8b3287a68bca193caf7be16a 2026-03-30 2026-03-30
HASH b86f07f60186e65dffca615cc69eaff1 2026-03-30 2026-03-30
HASH 9a6758045179dbe96ef34ab3811c3d1e 2026-03-30 2026-03-30
HASH 00671b085eb385deecb3fbad1316ca42 2026-03-30 2026-03-30
HASH d1642d1a13db6e2627136f4197f3a9e8 2026-03-30 2026-03-30
HASH 3a61b8da99f73e60a0c305ff7a5085e1 2026-03-30 2026-03-30
HASH 1f0e8b66339c5994a0e9ed5bdf8bc375 2026-03-30 2026-03-30
HASH b004470d1e888abc8f68cedc374a9ce4 2026-03-30 2026-03-30
URL https://lengitan.info/download 2026-03-30 2026-03-30
URL https://hesenorm.info/download/… 2026-03-30 2026-03-30
URL https://hesenorm.info/download/… 2026-03-30 2026-03-30
URL https://hesenorm.info/download/… 2026-03-30 2026-03-30
DOMAIN lengitan.info 2026-03-30 2026-03-30
DOMAIN hesenorm.info 2026-03-30 2026-03-30

Related Reports

« Back