정상 인증서를 악용하여 유포 중인 백도어 악성코드 주의!
2025-05-15 • ESTSecurity • Cyber threat report on CJOliveNetworks •
Alyac reports a backdoor distributed with a valid certificate from a well-known Korean company, likely to reduce user suspicion and evade detection. The malware is an SCR executable disguised with a PDF-like icon and extracts a decoy PDF to the user's temporary directory before dropping config.dat under the Public folder. The config.dat payload is a malicious DLL loaded through rundll32.exe, establishes persistence through a service or registry key depending on privileges, and communicates with C2 using either a DATA_CONF file or embedded RC4-decrypted configuration. Its supported commands include process execution, configuration changes, C2 switching, file deletion, persistence removal, file transfer, and screen capture.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | gsegse.dasfesfgsegsefsede.o-r.kr | 2025-05-15 | 2026-04-07 |
| HASH | 7ec88818697623a0130b1de42fa31335 | 2025-05-15 | 2025-05-30 |
| HASH | 580d7a5fdf78dd3e720b2ce772dc77e9 | 2025-05-15 | 2025-05-30 |