Andariel Group Exploiting Korean Asset Management Solutions (MeshAgent)
2024-03-19 • Ahnlab •
Andariel is described exploiting Korean asset management solutions during lateral movement to deploy AndarLoader and ModeLoader against Korean companies. The activity includes abuse of MeshAgent for remote control, Mshta-based retrieval of the JavaScript ModeLoader, and AndarLoader execution of downloaded .NET payloads in memory. After establishing backdoor access, the operators installed Mimikatz, modified WDigest-related settings to support credential theft, cleared Windows security logs, and used keylogging and clipboard logging with output stored under C:\Users\Public\game.db. Reported infrastructure includes AndarLoader C2 domains such as privacy.hopto[.]org and privatemake.bounceme[.]net, a MeshAgent server at 84.38.129[.]21, and multiple ModeLoader URLs under kro[.]kr and o-r[.]kr domains.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | privatemake.bounceme.net | 2023-08-22 | 2024-07-25 |
| HASH | 4f1b1124e34894398aa423200a8ab894 | 2024-03-11 | 2024-03-19 |
| HASH | 29efd64dd3c7fe1e2b022b7ad73a1ba5 | 2024-03-11 | 2024-03-19 |
| HASH | 2c69c4786ce663e58a3cc093c6d5b530 | 2024-03-11 | 2024-03-19 |
| HASH | a714b928bbc7cd480fed85e379966f95 | 2024-03-11 | 2024-03-19 |
| URL | http://www.ipservice.kro.kr/mod… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/modeRea… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/modeWri… | 2024-03-11 | 2024-03-19 |
| URL | http://www.ipservice.kro.kr/ind… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/modeVie… | 2024-03-11 | 2024-03-19 |
| URL | http://panda.ourhome.o-r.kr/mod… | 2024-03-11 | 2024-03-19 |
| URL | http://www.mssrv.kro.kr/view.php | 2024-03-11 | 2024-03-19 |
| URL | http://www.ipservice.kro.kr/vie… | 2024-03-11 | 2024-03-19 |
| URL | http://panda.ourhome.o-r.kr/mod… | 2024-03-11 | 2024-03-19 |
| URL | http://panda.ourhome.o-r.kr/vie… | 2024-03-11 | 2024-03-19 |
| DOMAIN | privacy.hopto.org | 2024-03-11 | 2024-03-19 |
| DOMAIN | panda.ourhome.o-r.kr | 2024-03-11 | 2024-03-19 |
| IPv4 | 84.38.129.21 | 2024-03-11 | 2024-03-19 |