'한독 합동 사이버 보안 권고' 관련 안랩 대응 현황
2023-03-20 • Ahnlab • Status of AhnLab's response to the ‘Korea-German Joint Cybersecurity Recommendation' •
AhnLab summarized its detections for IOCs published in the South Korea–Germany joint advisory on Kimsuky. The advisory said Kimsuky used Chromium browser extensions and Android app-developer support functions to steal account information, primarily targeting Korean Peninsula and North Korea specialists while warning that the techniques could scale beyond that audience. AhnLab mapped the released MD5 indicators to detections including Backdoor/JS.Agent for JavaScript extension components and Android-Trojan/Kimsuky or Android-Trojan/FastSpy for mobile samples. The source is an IOC-response note rather than a full intrusion narrative, so the operational value is the vendor detection mapping for the joint advisory artifacts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 012d5ffe697e33d81b9e7447f4aa338b | 2023-03-20 | 2023-05-16 |
| HASH | 582a033da897c967faade386ac30f604 | 2023-03-20 | 2023-05-16 |
| HASH | 04bb7e1a0b4f830ed7d1377a394bc717 | 2023-03-20 | 2023-04-19 |
| HASH | 89f97e1d68e274b03bc40f6e06e2ba9a | 2022-10-25 | 2023-04-19 |
| HASH | 3458daa0dffdc3fbb5c931f25d7a1ec0 | 2022-10-25 | 2023-04-19 |
| HASH | 51527624e7921a8157f820eb0ca78e29 | 2023-03-20 | 2023-03-20 |