3.20 공격 조직의 최신 오퍼레이션 '코인 매니저 (Coin Manager)'

2017-12-19 ESTSecurity 3.20 Attack organization's latest operation 'Coin Manager'

http://blog.alyac.co.kr/1448

Thumbnail for 3.20 공격 조직의 최신 오퍼레이션 '코인 매니저 (Coin Manager)'

ESRC identified an operation it calls Coin Manager, in which malware disguised as personal financial software was used against people connected to a specific Korean cryptocurrency exchange. The installer begins infection during setup, hides malicious code in resources, drops lsm.exe in a temporary folder, and attempts encrypted communication with three C2 servers. The article links the activity to earlier Korean government, media, financial, and private-sector intrusions through recurring Windows command-processor code patterns also seen in HWP, EXE spear-phishing, and DOC macro malware. Related document-based variants dropped leo.exe or lsm.exe, showed Korean development artifacts, reused the ISkyISea account name, and overlapped with the Canadian IP address 184.107.209.2, making the campaign important for tracking long-running Korean financial-sector targeting.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 184.107.209.2 2017-12-19 2018-10-02
IPv4 181.119.19.56 2017-12-19 2018-10-02
IPv4 80.91.118.45 2017-12-19 2018-10-02
IPv4 111.207.78.204 2017-12-19 2018-10-02
IPv4 50.205.193.11 2017-12-19 2017-12-19
IPv4 208.52.184.13 2017-12-19 2017-12-19
IPv4 41.131.29.59 2017-12-12 2017-12-19
IPv4 64.86.34.24 2017-12-12 2017-12-19
IPv4 176.35.250.93 2017-08-14 2017-12-19

Related Reports

« Back