크롬 원격 데스크톱을 악용하는 Kimsuky 공격 그룹

2023-06-28 Ahnlab Kimsuky attack group exploits Chrome Remote Desktop

https://asec.ahnlab.com/ko/54804/

Thumbnail for 크롬 원격 데스크톱을 악용하는 Kimsuky 공격 그룹

AhnLab reports that the North Korea-linked Kimsuky group abused Chrome Remote Desktop to maintain GUI control of infected Windows systems after deploying its AppleSeed backdoor. The observed chain used WSF or JavaScript malware that decoded AppleSeed with PowerShell and regsvr32, then installed additional tooling including browser credential stealers, an x64 RDP Patcher for multi-session access, Ngrok tunneling, and Chrome Remote Desktop. The credential stealer targeted Chrome, Microsoft Edge, and Naver Whale login data, while Ngrok and remote-desktop tooling helped operators reach systems behind NAT. The activity fits Kimsuky’s broader pattern of spear-phishing with malicious documents or scripts and layering custom malware with legitimate remote-access utilities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d6a38ffdbac241d69674fb142a420740 2023-06-28 2024-06-11
HASH 80f381a20d466e7a02ea37592a26b0b8 2023-06-28 2023-08-16
HASH b6d11017e02e7d569cfe203eda25f3aa 2023-06-28 2023-08-16
DOMAIN pikaros2.r-e.kr 2023-06-28 2023-08-16
DOMAIN getara1.mygamesonline.org 2023-06-28 2023-08-16
HASH 946e1e0d2e0d7785d2e2bcd3634bcd2a 2023-06-28 2023-07-06
HASH d2eb306ee0d7dabfe43610e0831bef49 2023-06-28 2023-07-06
URL http://pikaros2.r-e.kr/ 2023-06-28 2023-07-06
URL http://getara1.mygamesonline.org 2023-06-28 2023-06-28

Related Actors

Related Reports

« Back