보안 설치 프로그램으로 위장한 북한의 XCTDoor 실행 과정
2026-03-30 • Hauri • Execution Process of North Korea's XCTDoor Disguised as a Security Installer •
https://hauri.co.kr/security/security_view.html?intSeq=86&page=1&keyfield=&key=
Attachments
HAURI analyzed a Korean campaign that disguised malware as a required integrated security installer used for banking and public-sector websites, with the archive mimicking Veraport by using a similar filename and normal-looking installation flow. The infection chain used DLL sideloading through a legitimate Microsoft utility and a hidden malicious credui.dll, then created scripts under public user folders and scheduled tasks named office365 and AdobeUpdate to stage additional payloads. HAURI links the activity to a suspected North Korea-related threat group based on an encrypted string key referencing Songun, while the delivery infrastructure included lengitan[.]info and hesenorm[.]info download paths. The final XCTDoor payload, loaded from Microsoft Edge-like paths as Go DLL components, supports system information collection, monitoring, remote command execution, additional malware download, and control of infected hosts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f05d11616979d4b3a02024f0ec075b3b | 2026-03-30 | 2026-03-30 |
| HASH | 1a77dddae05b6bd96820902b6aee9cc3 | 2026-03-30 | 2026-03-30 |
| HASH | 97b14304761a2baa620007b2df8d6547 | 2026-03-30 | 2026-03-30 |
| HASH | c43a146f8b3287a68bca193caf7be16a | 2026-03-30 | 2026-03-30 |
| HASH | b86f07f60186e65dffca615cc69eaff1 | 2026-03-30 | 2026-03-30 |
| HASH | 9a6758045179dbe96ef34ab3811c3d1e | 2026-03-30 | 2026-03-30 |
| HASH | 00671b085eb385deecb3fbad1316ca42 | 2026-03-30 | 2026-03-30 |
| HASH | d1642d1a13db6e2627136f4197f3a9e8 | 2026-03-30 | 2026-03-30 |
| HASH | 3a61b8da99f73e60a0c305ff7a5085e1 | 2026-03-30 | 2026-03-30 |
| HASH | 1f0e8b66339c5994a0e9ed5bdf8bc375 | 2026-03-30 | 2026-03-30 |
| HASH | b004470d1e888abc8f68cedc374a9ce4 | 2026-03-30 | 2026-03-30 |
| URL | https://lengitan.info/download | 2026-03-30 | 2026-03-30 |
| URL | https://hesenorm.info/download/… | 2026-03-30 | 2026-03-30 |
| URL | https://hesenorm.info/download/… | 2026-03-30 | 2026-03-30 |
| URL | https://hesenorm.info/download/… | 2026-03-30 | 2026-03-30 |
| DOMAIN | lengitan.info | 2026-03-30 | 2026-03-30 |
| DOMAIN | hesenorm.info | 2026-03-30 | 2026-03-30 |