탈륨조직의 국내 암호화폐 지갑 펌웨어로 위장한 다차원 APT 공격 분석
2020-10-16 • ESTSecurity • Analysis of multidimensional APT attacks disguised as thallium organization's domestic cryptocurrency wallet firmware •
ESRC analyzed a Thallium-linked multi-platform cryptocurrency-wallet campaign that combined supply-chain style Android abuse with Windows installers disguised as legitimate domestic wallet firmware or update programs. The Android app was distributed through Google Play for a period and targeted wallet passcodes, while Windows variants modified bundled configuration or code to communicate with attacker-controlled C2 such as kasse-v1.hdac-wallet[.]com, kasse.hdac-tech[.]com, update.hdac-tech[.]com, and wallet.hdac-tech[.]com. ESRC tied the Windows samples to prior Thallium activity through matching string-encryption logic and the “<*IMPOSSIBLE*>” mutex observed in earlier June malware. The campaign illustrates Thallium’s use of trusted cryptocurrency software themes, direct email distribution, and selective tampering to steal wallet-related assets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 44.227.65.245 | 2020-10-16 | 2023-06-28 |
| IPv4 | 44.227.76.166 | 2020-10-16 | 2023-06-28 |
| DOMAIN | hdactech.info | 2020-10-16 | 2020-11-12 |
| HASH | 7fa4d0985ab3815937955768756e954… | 2020-10-16 | 2020-10-16 |
| HASH | 0d93df9863f04a11e7acea7d0c50e3d… | 2020-10-16 | 2020-10-16 |
| DOMAIN | kasse.hdac-tech.com | 2020-10-16 | 2020-10-16 |
| DOMAIN | update.hdac-tech.com | 2020-10-16 | 2020-10-16 |
| DOMAIN | kasse-v1.hdac-wallet.com | 2020-10-16 | 2020-10-16 |
| DOMAIN | wallet.hdac-tech.com | 2020-10-16 | 2020-10-16 |