Amadey Trojan distributed by DPRK-affiliated APT groups

2021-02-02 Bushidotoken

https://blog.bushidotoken.net/2021/02/amadey-trojan-distributed-by-dprk.html

Thumbnail for Amadey Trojan distributed by DPRK-affiliated APT groups

The report describes malicious Word documents themed around North Korean COVID-19 conditions that used VBA macros to drop a secondary payload and connect infected systems to attacker command-and-control infrastructure. The payload was identified as Amadey, a commodity trojan used for credential theft and remote control, retrieved from compromised web infrastructure after macros were enabled. The author notes that similar Amadey use had previously been observed in suspected DPRK activity by IssueMakersLab, Tencent, and ESTsecurity, and that domains related to C2 server 186.122.150[.]107 had been sinkholed in Microsoft action against Thallium. The campaign is relevant to DPRK tracking because it combines North Korea-themed lures, COVID-19 intelligence interest, and commodity malware that complicates attribution while lowering operational cost.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 189215def4bbba391070eaa31b850ed… 2021-02-02 2021-02-02
HASH 70fa2300d7932ab901c19878bf109bd… 2021-02-02 2021-02-02
HASH aab683fd88bc5f50e6eed4aaed3f53f… 2021-02-02 2021-02-02
URL https://www.rabadaun.com/wordpr… 2021-02-02 2021-02-02
URL https://fd-com.fr/wp-content/th… 2021-02-02 2021-02-02
HASH d1baefd0bdc7f3b0369c5b7126c3b98… 2021-02-01 2021-02-02
HASH efc139dc0e280a374065dc59c55a45b… 2021-02-01 2021-02-02
DOMAIN fd-com.fr 2021-02-01 2021-02-02
IPv4 108.62.118.185 2021-02-01 2021-02-02
IPv4 186.122.150.107 2021-02-01 2021-02-02

Related Reports

« Back