특정 군부대 유지보수 업체 대상으로 AppleSeed 유포
2022-07-21 • Ahnlab • AppleSeed distribution targeting a specific military unit maintenance contractor •
AhnLab observed AppleSeed malware being distributed against a maintenance contractor for a specific military unit, using a password-protected Excel file named to resemble an installation schedule for that unit. The source identifies AppleSeed as a backdoor mainly used by Kimsuky and notes that it can receive commands from a C2 server, download additional modules, and execute attacker-directed actions. The infection chain relied on enabling Excel macros, hiding the lure text after execution, and using mshta to download a follow-on script from attacker infrastructure. The script installed AppleSeed under %ProgramData%\Software\ControlSet\Service\ServiceScheduler.dll and launched it with regsvr32.exe, with IOCs including hime.dothome.co[.]kr and sign.dothome.co[.]kr.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1ac5b803205b1c3464941df2c21958e7 | 2022-07-21 | 2022-07-21 |
| HASH | a3786f14c85842861aa3493ec30be949 | 2022-07-21 | 2022-07-21 |
| URL | http://hime.dothome.co.kr/excha… | 2022-07-21 | 2022-07-21 |
| URL | http://sign.dothome.co.kr/login/ | 2022-07-21 | 2022-07-21 |
| DOMAIN | sign.dothome.co.kr | 2022-07-21 | 2022-07-21 |
| DOMAIN | hime.dothome.co.kr | 2022-07-21 | 2022-07-21 |