비트코인 1500만원 돌파하면서 김수키(Kimsuky) APT 조직 전방위 공격 중

2019-06-27 ESTSecurity As Bitcoin exceeds 15 million won, Kimsuky APT organization is attacking from all directions.

https://blog.alyac.co.kr/2389

Thumbnail for 비트코인 1500만원 돌파하면서 김수키(Kimsuky) APT 조직 전방위 공격 중

ESRC describes a Kimsuky-attributed APT attack that impersonated an ELYSIA token sale winner notification and targeted cryptocurrency users with a malicious HWP consent form. The document required the password “daybit” and contained an obfuscated EPS/PostScript component that decoded with an XOR 0xF0 routine before running shellcode and downloading additional payloads. The embedded payload reused strings seen in earlier Kimsuky activity and contacted smalldeal.mypressonline[.]com paths for posting and downloading data. A packed 32-bit DLL used a mutex to avoid duplicate execution, loaded another encoded payload from resources, attempted command-and-control through a Korean email service, and a later variant created an AhnLab-themed roaming directory while saving keystrokes to k001-style DAT files.

Related Actors

Related Reports

« Back