킴수키(Kimsuky)조직, '협의 이혼 의사 확인 신청서'를 위장한 QuasarRAT 유포 중!

2023-03-15 ESTSecurity Kimsuky distributing QuasarRAT disguised as an application to confirm intent to divorce

https://blog.alyac.co.kr/5103

Thumbnail for 킴수키(Kimsuky)조직, '협의 이혼 의사 확인 신청서'를 위장한 QuasarRAT 유포 중!

Kimsuky distributed a malicious Word document masquerading as an application to confirm mutual intent to divorce, using macros to install QuasarRAT. When the user enabled content, the decoy displayed a legitimate-looking divorce form while AutoOpen macro logic contacted attacker-controlled infrastructure, dropped version.ini, runps.vbs and conf.ps1, and repeatedly downloaded additional payloads before launching QuasarRAT. ESRC linked the activity to a North Korea-backed APT Smoke Screen operation and noted detections such as Trojan.Downloader.DOC.Gen, Backdoor.MSIL.Quasar.gen and Trojan.PowerShell.Agent, with C2 details withheld because the server remained reachable.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3c687fb0a1921a53f9c607938f25fdd1 2023-03-15 2023-05-24
HASH d4bb07f5a9462612cd0e8a9290e27fc8 2023-03-15 2023-05-24
HASH 8f411a46490016ac5d126b83cee65022 2023-03-15 2023-05-24
HASH e0cf0881de0fe35732bb02c1f4df02a3 2023-03-15 2023-05-24

Related Actors

Related Reports

« Back