북한 관련 법인을 노리는 CHM 악성코드

2023-03-14 Secu I CHM malware targeting North Korea-related organizations

https://stic.secui.com/main/main/threatInfo?id=119

A spear-phishing campaign targeted South Korean organizations related to North Korea by impersonating a cyber safety bureau email and attaching a ZIP archive containing a malicious CHM help file. Opening the CHM displayed legitimate-looking legal content while embedded script dropped and decoded Document.dat/Document.vbs, added a Run key for persistence, and executed PowerShell to retrieve additional code from attacker infrastructure. The downloaded script created a mutex, captured keystrokes and screenshots, and sent stolen data to C2 paths under ibsq.co.kr, with hashes and URLs supplied as supporting indicators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ibsq.co.kr 2023-03-14 2023-06-09
HASH ded83a6bd7438b34b058f2fe5ee54c7e 2023-03-14 2023-05-24
HASH 7773dfd975802295cf27e4b80b6492df 2023-03-14 2023-03-14
HASH 4930cfbdf0653952d769d95330d4f43b 2023-03-14 2023-03-14
URL http://ibsq.co/.kr/config/demo.… 2023-03-14 2023-03-14
URL http://ibsq.co/.kr/config/show.… 2023-03-14 2023-03-14
URL http://ibsq.co.kr/config 2023-03-14 2023-03-14
URL http://libsq.co.kr/config 2023-03-14 2023-03-14
URL http://libsq.co.kr/config/demo.… 2023-03-14 2023-03-14
DOMAIN ibsq.co 2023-03-14 2023-03-14
DOMAIN libsq.co.kr 2023-03-14 2023-03-14

Related Actors

Related Reports

« Back