A Deep-Dive Analysis of the NukeSped RATs
2019-10-23 • Fortinet •
https://www.fortinet.com/blog/threat-research/deep-analysis-nukesped-rat
FortiGuard Labs analyzed NukeSped RAT samples linked to North Korea’s HIDDEN COBRA activity and compared them with known FALLCHILL tooling. The samples used encrypted strings, dynamic API resolution, persistence through Run keys or services, and a remote-administration command set for process execution, payload retrieval, disk inspection, directory changes, and cleanup. Several samples carried Korean language identifiers and shared cryptographic and code-structure traits with earlier HIDDEN COBRA malware families. The report provides malware hashes and blocking context for defenders tracking DPRK-aligned RAT activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f8f7720785f7e75bd6407ac2acd63f9… | 2019-10-23 | 2020-03-09 |
| HASH | fe43bc385b30796f5e2d94dfa720903… | 2019-10-23 | 2020-03-09 |
| HASH | b05aae59b3c1d024b19c88448811deb… | 2019-10-23 | 2020-03-09 |
| HASH | 0608e411348905145a267a9beaf5cd3… | 2019-10-23 | 2020-03-09 |
| HASH | c66ef8652e15b579b409170658c95d3… | 2019-10-23 | 2020-03-09 |
| HASH | 1a01b8a4c505db70f9e199337ce7f49… | 2019-10-23 | 2020-03-09 |
| HASH | 73dcb7639c1f81d3f7c4931d32787bd… | 2019-10-23 | 2020-03-09 |
| HASH | 32ec329301aa4547b4ef4800159940f… | 2019-10-23 | 2020-03-09 |
| HASH | 084b21bc32ee19af98f85aee8204a14… | 2019-10-23 | 2020-03-09 |
| HASH | 8a1d57ee05d29a730864299376b830a… | 2019-10-23 | 2020-03-09 |
| IPv4 | 218.255.24.226 | 2019-10-23 | 2020-02-25 |
| IPv4 | 119.18.230.253 | 2019-10-23 | 2020-02-25 |