보안 업데이트 설치 프로그램으로 위장한 악성코드 유포 주의
2023-06-09 • Ahnlab • Beware of spreading malware disguised as a security update installation program •
AhnLab and South Korea’s National Cyber Security Center joint analysis group reported malware distributed as a fake security update installer by a state-backed hacking group. The malicious installer was built with Inno Setup and contained an install_script.iss script that wrote malicious files under C:\ProgramData and registered installation information in Programs and Features. After execution, the malware registered itself in startup-related registry locations for persistence, stole system information, sent it to the attacker’s C&C server, and could execute additional remote commands. AhnLab identified the threat as Dropper/Win.FakeGovuki and provided representative indicators including MD5 c5e0a2b881a60fb3440bb78e9920dccd and the defanged domain pita1.sportsontheweb[.]net.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c5e0a2b881a60fb3440bb78e9920dccd | 2023-06-09 | 2023-08-16 |
| DOMAIN | pita1.sportsontheweb.net | 2023-06-09 | 2023-08-16 |