사용자 정보를 탈취하는 CHM 악성코드 국내 유포

2024-04-25 Ahnlab 3. bootservice.php?query=1 (Fileless)

https://asec.ahnlab.com/ko/64612/

Thumbnail for 사용자 정보를 탈취하는 CHM 악성코드 국내 유포

AhnLab reported CHM malware distribution against South Korean users, connecting the lure family to prior Kimsuky activity that used LNK, DOC, OneNote, and press-release themes. The CHM file runs embedded script content, creates files under the user profile, and ultimately sends user information and keylogging data to attacker infrastructure, making it a credential and information theft threat.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b2c74dbf20824477c3e139b48833041b 2024-04-25 2024-05-08

Related Actors

Related Reports

« Back