AhnLab EDR을 활용한 Kimsuky 그룹의 스피어 피싱 공격 탐지 (AppleSeed, AlphaSeed)

2024-02-08 Ahnlab Detection of spear phishing attacks by Kimsuky group using AhnLab EDR (AppleSeed, AlphaSeed)

https://asec.ahnlab.com/ko/61518/

Thumbnail for AhnLab EDR을 활용한 Kimsuky 그룹의 스피어 피싱 공격 탐지 (AppleSeed, AlphaSeed)

Kimsuky uses spear phishing emails with VBS or JavaScript files disguised as documents to install AppleSeed and, in the observed case, AlphaSeed on targeted systems. The lures vary by target, including government-style documents for diplomacy and defense, business forms for companies, and personal or shopping documents for individuals. The chain creates encrypted payloads under ProgramData, decrypts them with certutil, and runs DLL malware through PowerShell and regsvr32. AppleSeed provides backdoor, downloader, keylogging, screenshot, file collection, and C2 functions, while AlphaSeed is a Go malware family that uses ChromeDP and email-based C2 authentication through cookies.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7756b4230adfa16e18142d1dbe6934af 2024-02-08 2025-06-09
DOMAIN peras1.n-e.kr 2024-02-08 2025-06-09
HASH 486370be06493d78a9922b3a6e424909 2024-02-08 2024-02-08
HASH a0dd33b6b8c3ac9bee46a95586df345f 2024-02-08 2024-02-08
HASH 8b77608db042b225ae8f59276ee3a165 2024-02-08 2024-02-08
URL http://peras1.n-e.kr/ 2024-02-08 2024-02-08

Related Actors

Related Reports

« Back