킴수키(Kimsuky)조직의 'Mail Online Security' 프로그램 위장 공격 주의!
2023-06-26 • ESTSecurity • Beware of spoofing attacks from the Kimsuky organization's 'Mail Online Security' program! •
ESTsecurity’s ESRC reports a Kimsuky campaign distributing malware disguised as a legitimate “Mail Online Security” installer, assessed as a variant of activity previously warned about by South Korea’s NCSC/KISA. The lure used an ISO containing setup.exe with security-program branding; execution displayed a fake installer while unrar.exe unpacked password-protected plugin DLLs in the background. The DLL chain injected a payload into Chrome, copied Chrome into ProgramData, placed a malicious version.dll for DLL hijacking, registered “Chrome Updater” for autorun, and ultimately ran a command-and-control component. ESRC linked the activity to Kimsuky’s Blue Estimate campaign and noted capabilities including self-deletion, file upload/download, and process PID/name reporting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 042fb52b45f396d7792785d5b2cf0865 | 2023-06-26 | 2023-08-16 |
| HASH | 88d09f09a3b717fee194f7b13186a215 | 2023-06-26 | 2023-08-16 |
| HASH | eb063fe691240f22acd8921f47609a3c | 2023-06-26 | 2023-08-16 |
| HASH | e8c32a91d00c6dc1eda38efdfdd9a05f | 2023-06-26 | 2023-08-16 |
| HASH | 3c165e9f3b996ac5895e2e4aa223ff77 | 2023-06-26 | 2023-08-16 |