탈륨조직의 국내 암호화폐 지갑 펌웨어로 위장한 다차원 APT 공격 분석

2020-10-16 ESTSecurity Analysis of multidimensional APT attacks disguised as thallium organization's domestic cryptocurrency wallet firmware

https://blog.alyac.co.kr/3310

Thumbnail for 탈륨조직의 국내 암호화폐 지갑 펌웨어로 위장한 다차원 APT 공격 분석

ESRC analyzed a Thallium-linked multi-platform cryptocurrency-wallet campaign that combined supply-chain style Android abuse with Windows installers disguised as legitimate domestic wallet firmware or update programs. The Android app was distributed through Google Play for a period and targeted wallet passcodes, while Windows variants modified bundled configuration or code to communicate with attacker-controlled C2 such as kasse-v1.hdac-wallet[.]com, kasse.hdac-tech[.]com, update.hdac-tech[.]com, and wallet.hdac-tech[.]com. ESRC tied the Windows samples to prior Thallium activity through matching string-encryption logic and the “<*IMPOSSIBLE*>” mutex observed in earlier June malware. The campaign illustrates Thallium’s use of trusted cryptocurrency software themes, direct email distribution, and selective tampering to steal wallet-related assets.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 44.227.65.245 2020-10-16 2023-06-28
IPv4 44.227.76.166 2020-10-16 2023-06-28
DOMAIN hdactech.info 2020-10-16 2020-11-12
HASH 7fa4d0985ab3815937955768756e954… 2020-10-16 2020-10-16
HASH 0d93df9863f04a11e7acea7d0c50e3d… 2020-10-16 2020-10-16
DOMAIN kasse.hdac-tech.com 2020-10-16 2020-10-16
DOMAIN update.hdac-tech.com 2020-10-16 2020-10-16
DOMAIN kasse-v1.hdac-wallet.com 2020-10-16 2020-10-16
DOMAIN wallet.hdac-tech.com 2020-10-16 2020-10-16

Related Actors

Related Reports

« Back