킴수키(Kimsuky)조직의 'Mail Online Security' 프로그램 위장 공격 주의!

2023-06-26 ESTSecurity Beware of spoofing attacks from the Kimsuky organization's 'Mail Online Security' program!

https://blog.alyac.co.kr/5185

Thumbnail for 킴수키(Kimsuky)조직의 'Mail Online Security' 프로그램 위장 공격 주의!

ESTsecurity’s ESRC reports a Kimsuky campaign distributing malware disguised as a legitimate “Mail Online Security” installer, assessed as a variant of activity previously warned about by South Korea’s NCSC/KISA. The lure used an ISO containing setup.exe with security-program branding; execution displayed a fake installer while unrar.exe unpacked password-protected plugin DLLs in the background. The DLL chain injected a payload into Chrome, copied Chrome into ProgramData, placed a malicious version.dll for DLL hijacking, registered “Chrome Updater” for autorun, and ultimately ran a command-and-control component. ESRC linked the activity to Kimsuky’s Blue Estimate campaign and noted capabilities including self-deletion, file upload/download, and process PID/name reporting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 042fb52b45f396d7792785d5b2cf0865 2023-06-26 2023-08-16
HASH 88d09f09a3b717fee194f7b13186a215 2023-06-26 2023-08-16
HASH eb063fe691240f22acd8921f47609a3c 2023-06-26 2023-08-16
HASH e8c32a91d00c6dc1eda38efdfdd9a05f 2023-06-26 2023-08-16
HASH 3c165e9f3b996ac5895e2e4aa223ff77 2023-06-26 2023-08-16

Related Actors

Related Reports

« Back