북한 관련 법인을 노리는 CHM 악성코드
2023-03-14 • Secu I • CHM malware targeting North Korea-related organizations •
A spear-phishing campaign targeted South Korean organizations related to North Korea by impersonating a cyber safety bureau email and attaching a ZIP archive containing a malicious CHM help file. Opening the CHM displayed legitimate-looking legal content while embedded script dropped and decoded Document.dat/Document.vbs, added a Run key for persistence, and executed PowerShell to retrieve additional code from attacker infrastructure. The downloaded script created a mutex, captured keystrokes and screenshots, and sent stolen data to C2 paths under ibsq.co.kr, with hashes and URLs supplied as supporting indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ibsq.co.kr | 2023-03-14 | 2023-06-09 |
| HASH | ded83a6bd7438b34b058f2fe5ee54c7e | 2023-03-14 | 2023-05-24 |
| HASH | 7773dfd975802295cf27e4b80b6492df | 2023-03-14 | 2023-03-14 |
| HASH | 4930cfbdf0653952d769d95330d4f43b | 2023-03-14 | 2023-03-14 |
| URL | http://ibsq.co/.kr/config/demo.… | 2023-03-14 | 2023-03-14 |
| URL | http://ibsq.co/.kr/config/show.… | 2023-03-14 | 2023-03-14 |
| URL | http://ibsq.co.kr/config | 2023-03-14 | 2023-03-14 |
| URL | http://libsq.co.kr/config | 2023-03-14 | 2023-03-14 |
| URL | http://libsq.co.kr/config/demo.… | 2023-03-14 | 2023-03-14 |
| DOMAIN | ibsq.co | 2023-03-14 | 2023-03-14 |
| DOMAIN | libsq.co.kr | 2023-03-14 | 2023-03-14 |