특정 군부대 유지보수 업체 대상으로 AppleSeed 유포

2022-07-21 Ahnlab AppleSeed distribution targeting a specific military unit maintenance contractor

https://asec.ahnlab.com/ko/36918/

Thumbnail for 특정 군부대 유지보수 업체 대상으로 AppleSeed 유포

AhnLab observed AppleSeed malware being distributed against a maintenance contractor for a specific military unit, using a password-protected Excel file named to resemble an installation schedule for that unit. The source identifies AppleSeed as a backdoor mainly used by Kimsuky and notes that it can receive commands from a C2 server, download additional modules, and execute attacker-directed actions. The infection chain relied on enabling Excel macros, hiding the lure text after execution, and using mshta to download a follow-on script from attacker infrastructure. The script installed AppleSeed under %ProgramData%\Software\ControlSet\Service\ServiceScheduler.dll and launched it with regsvr32.exe, with IOCs including hime.dothome.co[.]kr and sign.dothome.co[.]kr.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1ac5b803205b1c3464941df2c21958e7 2022-07-21 2022-07-21
HASH a3786f14c85842861aa3493ec30be949 2022-07-21 2022-07-21
URL http://hime.dothome.co.kr/excha… 2022-07-21 2022-07-21
URL http://sign.dothome.co.kr/login/ 2022-07-21 2022-07-21
DOMAIN sign.dothome.co.kr 2022-07-21 2022-07-21
DOMAIN hime.dothome.co.kr 2022-07-21 2022-07-21

Related Actors

Related Reports

« Back