Andariel Group Exploiting Korean Asset Management Solutions (MeshAgent)

2024-03-19 Ahnlab

https://asec.ahnlab.com/en/63192/

Thumbnail for Andariel Group Exploiting Korean Asset Management Solutions (MeshAgent)

Andariel is described exploiting Korean asset management solutions during lateral movement to deploy AndarLoader and ModeLoader against Korean companies. The activity includes abuse of MeshAgent for remote control, Mshta-based retrieval of the JavaScript ModeLoader, and AndarLoader execution of downloaded .NET payloads in memory. After establishing backdoor access, the operators installed Mimikatz, modified WDigest-related settings to support credential theft, cleared Windows security logs, and used keylogging and clipboard logging with output stored under C:\Users\Public\game.db. Reported infrastructure includes AndarLoader C2 domains such as privacy.hopto[.]org and privatemake.bounceme[.]net, a MeshAgent server at 84.38.129[.]21, and multiple ModeLoader URLs under kro[.]kr and o-r[.]kr domains.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN privatemake.bounceme.net 2023-08-22 2024-07-25
HASH 4f1b1124e34894398aa423200a8ab894 2024-03-11 2024-03-19
HASH 29efd64dd3c7fe1e2b022b7ad73a1ba5 2024-03-11 2024-03-19
HASH 2c69c4786ce663e58a3cc093c6d5b530 2024-03-11 2024-03-19
HASH a714b928bbc7cd480fed85e379966f95 2024-03-11 2024-03-19
URL http://www.ipservice.kro.kr/mod… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/modeRea… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/modeWri… 2024-03-11 2024-03-19
URL http://www.ipservice.kro.kr/ind… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/modeVie… 2024-03-11 2024-03-19
URL http://panda.ourhome.o-r.kr/mod… 2024-03-11 2024-03-19
URL http://www.mssrv.kro.kr/view.php 2024-03-11 2024-03-19
URL http://www.ipservice.kro.kr/vie… 2024-03-11 2024-03-19
URL http://panda.ourhome.o-r.kr/mod… 2024-03-11 2024-03-19
URL http://panda.ourhome.o-r.kr/vie… 2024-03-11 2024-03-19
DOMAIN privacy.hopto.org 2024-03-11 2024-03-19
DOMAIN panda.ourhome.o-r.kr 2024-03-11 2024-03-19
IPv4 84.38.129.21 2024-03-11 2024-03-19

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back