APT-C-55(Kimsuky)组织以IBM公司安全产品为诱饵的攻击活动分析
2022-11-29 • Qihoo360 • APT-C-55 (Kimsuky) attack campaign using IBM security products as bait •
360 Threat Intelligence Center attributes an attack to APT-C-55, also known as Kimsuky, that used IBM Security Trusteer Rapport as a lure to deliver BabyShark-related components. The malicious ISO contained a BAT script and a legitimate-looking installer; execution installed the decoy product while using scripts and compromised infrastructure to download backdoor code and collect host information.
Indicators of Compromise
Related Actors
Related Reports
Shares tags: Kimsuky, APT-C-55 • Same author: Qihoo360
Shares tags: Kimsuky, APT-C-55 • Same author: Qihoo360
Shares tags: Kimsuky, APT-C-55 • Same author: Qihoo360
2022-11-25 •
60% Match
#Kimsuky
Shares tag: Kimsuky • Published within a week
2022-11-25 •
60% Match
#Kimsuky
Shares tag: Kimsuky • Published within a week
Shares tag: Kimsuky • Published within a week