APT Attacks Using Cloud Storage
2024-06-11 • Ahnlab •
The threat actor appears to set the attack targets in advance and distribute malware after continuously collecting relevant information. The malware that is launched through the above process is XenoRAT which can perform various malicious behaviors such as loading malware, launching and terminating processes, and communicating with the C2 server based on the threat actor’s commands. Given that the threat actor also uses files disguised as documents such as money deposit contracts, insurance, and loans that include the personal information of specific individuals, it appears that they distribute malware to specific designated targets. [1][2][3] The threat actors mainly upload malicious scripts, RAT malware strains, and decoy documents onto the cloud servers to perform attacks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 159.100.29.122 | 2024-05-23 | 2024-08-21 |
| HASH | dd2988c792b0252db4c39309e6cb2c48 | 2024-05-23 | 2024-06-11 |
| HASH | f396bf5ff64656b592fe3d665eab8aa3 | 2024-05-23 | 2024-06-11 |
| HASH | c45d209f666f77d70bed61e6fca48bc2 | 2024-05-23 | 2024-06-11 |
| HASH | 6ad00d48fdce8dc632b13f6c2438f893 | 2024-05-23 | 2024-06-11 |
| HASH | d9d9b8375f74812c41a1cd9abce25ac9 | 2024-05-23 | 2024-06-11 |
| HASH | bcb0a6360f057475c63fb16e61fb3adc | 2024-05-23 | 2024-06-11 |
| HASH | 52e5d2cd15ea7d0928e90b18039ec6c6 | 2024-05-23 | 2024-06-11 |
| HASH | 5d2fdc098d1e1a7674a40ef9140058ed | 2024-05-23 | 2024-06-11 |
| HASH | 66b5ffb611505f0067c868dfa84aea60 | 2024-05-23 | 2024-06-11 |
| HASH | 238cd8f609b06258ab8b4ded82ebbff8 | 2024-05-23 | 2024-06-11 |
| [email protected] | 2024-05-23 | 2024-06-11 | |
| [email protected] | 2024-05-23 | 2024-06-11 | |
| [email protected] | 2024-05-23 | 2024-06-11 | |
| [email protected] | 2024-05-23 | 2024-06-11 | |
| [email protected] | 2024-05-23 | 2024-06-11 |