A Deep-Dive Analysis of the NukeSped RATs

2019-10-23 Fortinet

https://www.fortinet.com/blog/threat-research/deep-analysis-nukesped-rat

Thumbnail for A Deep-Dive Analysis of the NukeSped RATs

FortiGuard Labs analyzed NukeSped RAT samples linked to North Korea’s HIDDEN COBRA activity and compared them with known FALLCHILL tooling. The samples used encrypted strings, dynamic API resolution, persistence through Run keys or services, and a remote-administration command set for process execution, payload retrieval, disk inspection, directory changes, and cleanup. Several samples carried Korean language identifiers and shared cryptographic and code-structure traits with earlier HIDDEN COBRA malware families. The report provides malware hashes and blocking context for defenders tracking DPRK-aligned RAT activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f8f7720785f7e75bd6407ac2acd63f9… 2019-10-23 2020-03-09
HASH fe43bc385b30796f5e2d94dfa720903… 2019-10-23 2020-03-09
HASH b05aae59b3c1d024b19c88448811deb… 2019-10-23 2020-03-09
HASH 0608e411348905145a267a9beaf5cd3… 2019-10-23 2020-03-09
HASH c66ef8652e15b579b409170658c95d3… 2019-10-23 2020-03-09
HASH 1a01b8a4c505db70f9e199337ce7f49… 2019-10-23 2020-03-09
HASH 73dcb7639c1f81d3f7c4931d32787bd… 2019-10-23 2020-03-09
HASH 32ec329301aa4547b4ef4800159940f… 2019-10-23 2020-03-09
HASH 084b21bc32ee19af98f85aee8204a14… 2019-10-23 2020-03-09
HASH 8a1d57ee05d29a730864299376b830a… 2019-10-23 2020-03-09
IPv4 218.255.24.226 2019-10-23 2020-02-25
IPv4 119.18.230.253 2019-10-23 2020-02-25

Related Actors

Related Reports

« Back