크롬 원격 데스크톱을 악용하는 Kimsuky 공격 그룹
2023-06-28 • Ahnlab • Kimsuky attack group exploits Chrome Remote Desktop •
AhnLab reports that the North Korea-linked Kimsuky group abused Chrome Remote Desktop to maintain GUI control of infected Windows systems after deploying its AppleSeed backdoor. The observed chain used WSF or JavaScript malware that decoded AppleSeed with PowerShell and regsvr32, then installed additional tooling including browser credential stealers, an x64 RDP Patcher for multi-session access, Ngrok tunneling, and Chrome Remote Desktop. The credential stealer targeted Chrome, Microsoft Edge, and Naver Whale login data, while Ngrok and remote-desktop tooling helped operators reach systems behind NAT. The activity fits Kimsuky’s broader pattern of spear-phishing with malicious documents or scripts and layering custom malware with legitimate remote-access utilities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d6a38ffdbac241d69674fb142a420740 | 2023-06-28 | 2024-06-11 |
| HASH | 80f381a20d466e7a02ea37592a26b0b8 | 2023-06-28 | 2023-08-16 |
| HASH | b6d11017e02e7d569cfe203eda25f3aa | 2023-06-28 | 2023-08-16 |
| DOMAIN | pikaros2.r-e.kr | 2023-06-28 | 2023-08-16 |
| DOMAIN | getara1.mygamesonline.org | 2023-06-28 | 2023-08-16 |
| HASH | 946e1e0d2e0d7785d2e2bcd3634bcd2a | 2023-06-28 | 2023-07-06 |
| HASH | d2eb306ee0d7dabfe43610e0831bef49 | 2023-06-28 | 2023-07-06 |
| URL | http://pikaros2.r-e.kr/ | 2023-06-28 | 2023-07-06 |
| URL | http://getara1.mygamesonline.org | 2023-06-28 | 2023-06-28 |