원자력 발전소 관련 기업 대상으로 AppleSeed 유포
2022-10-27 • Ahnlab • Distribute AppleSeed to companies related to nuclear power plants •
AhnLab reports AppleSeed malware distribution against organizations related to nuclear power plants. The attack used spear-phishing and document-themed lures to deliver malware associated with Kimsuky-style operations, with AppleSeed functioning as a backdoor for command execution and follow-on control. The report describes how the malware infection chain used disguised files and attacker infrastructure to establish access to targeted environments. It emphasizes that energy-sector organizations should treat document lures and AppleSeed indicators as high-priority threats.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ba83312ea92c284c710bcc0906a29fb1 | 2022-10-27 | 2022-10-27 |
| HASH | 55a9a935b36da90fb5a7ab814d567a40 | 2022-10-27 | 2022-10-27 |
| URL | http://ndt.info.gf/index.php | 2022-10-27 | 2022-10-27 |
| DOMAIN | ndt.info.gf | 2022-10-27 | 2022-10-27 |