Amadey Trojan distributed by DPRK-affiliated APT groups
2021-02-02 • Bushidotoken •
https://blog.bushidotoken.net/2021/02/amadey-trojan-distributed-by-dprk.html
The report describes malicious Word documents themed around North Korean COVID-19 conditions that used VBA macros to drop a secondary payload and connect infected systems to attacker command-and-control infrastructure. The payload was identified as Amadey, a commodity trojan used for credential theft and remote control, retrieved from compromised web infrastructure after macros were enabled. The author notes that similar Amadey use had previously been observed in suspected DPRK activity by IssueMakersLab, Tencent, and ESTsecurity, and that domains related to C2 server 186.122.150[.]107 had been sinkholed in Microsoft action against Thallium. The campaign is relevant to DPRK tracking because it combines North Korea-themed lures, COVID-19 intelligence interest, and commodity malware that complicates attribution while lowering operational cost.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 189215def4bbba391070eaa31b850ed… | 2021-02-02 | 2021-02-02 |
| HASH | 70fa2300d7932ab901c19878bf109bd… | 2021-02-02 | 2021-02-02 |
| HASH | aab683fd88bc5f50e6eed4aaed3f53f… | 2021-02-02 | 2021-02-02 |
| URL | https://www.rabadaun.com/wordpr… | 2021-02-02 | 2021-02-02 |
| URL | https://fd-com.fr/wp-content/th… | 2021-02-02 | 2021-02-02 |
| HASH | d1baefd0bdc7f3b0369c5b7126c3b98… | 2021-02-01 | 2021-02-02 |
| HASH | efc139dc0e280a374065dc59c55a45b… | 2021-02-01 | 2021-02-02 |
| DOMAIN | fd-com.fr | 2021-02-01 | 2021-02-02 |
| IPv4 | 108.62.118.185 | 2021-02-01 | 2021-02-02 |
| IPv4 | 186.122.150.107 | 2021-02-01 | 2021-02-02 |