정상 인증서를 악용하여 유포 중인 백도어 악성코드 주의!

2025-05-15 ESTSecurity Cyber threat report on CJOliveNetworks

https://alyacofficialblog.tistory.com/5564

Thumbnail for 정상 인증서를 악용하여 유포 중인 백도어 악성코드 주의!

Alyac reports a backdoor distributed with a valid certificate from a well-known Korean company, likely to reduce user suspicion and evade detection. The malware is an SCR executable disguised with a PDF-like icon and extracts a decoy PDF to the user's temporary directory before dropping config.dat under the Public folder. The config.dat payload is a malicious DLL loaded through rundll32.exe, establishes persistence through a service or registry key depending on privileges, and communicates with C2 using either a DATA_CONF file or embedded RC4-decrypted configuration. Its supported commands include process execution, configuration changes, C2 switching, file deletion, persistence removal, file transfer, and screen capture.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN gsegse.dasfesfgsegsefsede.o-r.kr 2025-05-15 2026-04-07
HASH 7ec88818697623a0130b1de42fa31335 2025-05-15 2025-05-30
HASH 580d7a5fdf78dd3e720b2ce772dc77e9 2025-05-15 2025-05-30

Related Reports

« Back