3.20 공격 조직의 최신 오퍼레이션 '코인 매니저 (Coin Manager)'
2017-12-19 • ESTSecurity • 3.20 Attack organization's latest operation 'Coin Manager' •
ESRC identified an operation it calls Coin Manager, in which malware disguised as personal financial software was used against people connected to a specific Korean cryptocurrency exchange. The installer begins infection during setup, hides malicious code in resources, drops lsm.exe in a temporary folder, and attempts encrypted communication with three C2 servers. The article links the activity to earlier Korean government, media, financial, and private-sector intrusions through recurring Windows command-processor code patterns also seen in HWP, EXE spear-phishing, and DOC macro malware. Related document-based variants dropped leo.exe or lsm.exe, showed Korean development artifacts, reused the ISkyISea account name, and overlapped with the Canadian IP address 184.107.209.2, making the campaign important for tracking long-running Korean financial-sector targeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 184.107.209.2 | 2017-12-19 | 2018-10-02 |
| IPv4 | 181.119.19.56 | 2017-12-19 | 2018-10-02 |
| IPv4 | 80.91.118.45 | 2017-12-19 | 2018-10-02 |
| IPv4 | 111.207.78.204 | 2017-12-19 | 2018-10-02 |
| IPv4 | 50.205.193.11 | 2017-12-19 | 2017-12-19 |
| IPv4 | 208.52.184.13 | 2017-12-19 | 2017-12-19 |
| IPv4 | 41.131.29.59 | 2017-12-12 | 2017-12-19 |
| IPv4 | 64.86.34.24 | 2017-12-12 | 2017-12-19 |
| IPv4 | 176.35.250.93 | 2017-08-14 | 2017-12-19 |