'한독 합동 사이버 보안 권고' 관련 안랩 대응 현황

2023-03-20 Ahnlab Status of AhnLab's response to the ‘Korea-German Joint Cybersecurity Recommendation'

https://asec.ahnlab.com/ko/49964/

Thumbnail for '한독 합동 사이버 보안 권고' 관련 안랩 대응 현황

AhnLab summarized its detections for IOCs published in the South Korea–Germany joint advisory on Kimsuky. The advisory said Kimsuky used Chromium browser extensions and Android app-developer support functions to steal account information, primarily targeting Korean Peninsula and North Korea specialists while warning that the techniques could scale beyond that audience. AhnLab mapped the released MD5 indicators to detections including Backdoor/JS.Agent for JavaScript extension components and Android-Trojan/Kimsuky or Android-Trojan/FastSpy for mobile samples. The source is an IOC-response note rather than a full intrusion narrative, so the operational value is the vendor detection mapping for the joint advisory artifacts.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 012d5ffe697e33d81b9e7447f4aa338b 2023-03-20 2023-05-16
HASH 582a033da897c967faade386ac30f604 2023-03-20 2023-05-16
HASH 04bb7e1a0b4f830ed7d1377a394bc717 2023-03-20 2023-04-19
HASH 89f97e1d68e274b03bc40f6e06e2ba9a 2022-10-25 2023-04-19
HASH 3458daa0dffdc3fbb5c931f25d7a1ec0 2022-10-25 2023-04-19
HASH 51527624e7921a8157f820eb0ca78e29 2023-03-20 2023-03-20

Related Actors

Related Reports

« Back