사용자 정보를 탈취하는 CHM 악성코드 국내 유포
2024-04-25 • Ahnlab • 3. bootservice.php?query=1 (Fileless) •
AhnLab reported CHM malware distribution against South Korean users, connecting the lure family to prior Kimsuky activity that used LNK, DOC, OneNote, and press-release themes. The CHM file runs embedded script content, creates files under the user profile, and ultimately sends user information and keylogging data to attacker infrastructure, making it a credential and information theft threat.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b2c74dbf20824477c3e139b48833041b | 2024-04-25 | 2024-05-08 |
Related Actors
Related Reports
Shares tags: CHM, Kimsuky • Shares 1 IOC • Same author: Ahnlab • Published within a month
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
Shares tags: CHM, Kimsuky
Shares tags: CHM, Kimsuky
Shares tags: CHM, Kimsuky • Same author: Ahnlab
Shares tags: CHM, Kimsuky • Same author: Ahnlab