AhnLab EDR을 활용한 Kimsuky 그룹의 스피어 피싱 공격 탐지 (AppleSeed, AlphaSeed)
2024-02-08 • Ahnlab • Detection of spear phishing attacks by Kimsuky group using AhnLab EDR (AppleSeed, AlphaSeed) •
Kimsuky uses spear phishing emails with VBS or JavaScript files disguised as documents to install AppleSeed and, in the observed case, AlphaSeed on targeted systems. The lures vary by target, including government-style documents for diplomacy and defense, business forms for companies, and personal or shopping documents for individuals. The chain creates encrypted payloads under ProgramData, decrypts them with certutil, and runs DLL malware through PowerShell and regsvr32. AppleSeed provides backdoor, downloader, keylogging, screenshot, file collection, and C2 functions, while AlphaSeed is a Go malware family that uses ChromeDP and email-based C2 authentication through cookies.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7756b4230adfa16e18142d1dbe6934af | 2024-02-08 | 2025-06-09 |
| DOMAIN | peras1.n-e.kr | 2024-02-08 | 2025-06-09 |
| HASH | 486370be06493d78a9922b3a6e424909 | 2024-02-08 | 2024-02-08 |
| HASH | a0dd33b6b8c3ac9bee46a95586df345f | 2024-02-08 | 2024-02-08 |
| HASH | 8b77608db042b225ae8f59276ee3a165 | 2024-02-08 | 2024-02-08 |
| URL | http://peras1.n-e.kr/ | 2024-02-08 | 2024-02-08 |