APT-C-55(Kimsuky)组织使用韩文域名进行恶意活动

2023-08-28 Qihoo360 APT-C-55 (Kimsuky) organization uses Korean domain names to conduct malicious activities

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247493300&idx=1&sn=614dda72d95b5dfd732916aec0662598&chksm=f9c1d5bdceb65cab316de9e368fef6a997b82e96ed1a70b9b53ea8ae3c5698a8d4c95488e956&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-55(Kimsuky)组织使用韩文域名进行恶意活动

360 Threat Intelligence Center reports that APT-C-55/Kimsuky used Korean-language domains in a multi-stage malware campaign. The initial LNK payload decrypted and dropped a VBS script, which downloaded additional VBS code, created a scheduled task for persistence, and fetched PowerShell used to collect host information and exfiltrate it. Later stages downloaded obfuscated PowerShell from xn--vn4b27hka971hbue.kr infrastructure to capture clipboard contents and keystrokes, while related malicious macro samples fetched payloads from Korean-domain URLs. The report characterizes the activity as part of Kimsuky’s continuing attacks against Korean government targets using social engineering, spear phishing, watering holes, malicious HWP or macro files, PE payloads, and LNK files.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://partybbq.co.kr/src/bbs/c… 2023-08-28 2024-11-13
DOMAIN partybbq.co.kr 2023-05-24 2024-11-13
HASH 433a2a49a84545f23a038f3584f28b4a 2023-06-09 2023-12-18
HASH cadbf74e83332a3bd95721a791e2f35c 2023-08-28 2023-08-28
HASH 86f5d04ad7c6cefd795ae717d9752737 2023-08-28 2023-08-28
HASH f2e74b749c04936cfc253e05da8de4d0 2023-08-28 2023-08-28
HASH 8516b530ebdee3b320c7e9ca0f1fec78 2023-08-28 2023-08-28
URL http://xn--vn4b27hka971hbue.kr/… 2023-08-28 2023-08-28
URL http://xn-vn4b27hka971hbue.kr/s… 2023-08-28 2023-08-28
URL http://xn--vn4b27hka971hbue.kr/… 2023-08-28 2023-08-28
URL http://xn--vn4b27hka971hbue.kr/… 2023-08-28 2023-08-28
URL http://xn--vn4b27hka971hbue.kr/… 2023-08-28 2023-08-28
URL http://xn--vn4b27hka971hbue.kr/… 2023-08-28 2023-08-28
DOMAIN xn-vn4b27hka971hbue.kr 2023-08-28 2023-08-28
HASH 955170427d0c4f9c23f7b8507a6003aa 2023-06-09 2023-08-28
DOMAIN xn--vn4b27hka971hbue.kr 2023-06-06 2023-08-28
HASH 91d0b01a6a4a0b8edadf1df6a8e68d20 2023-04-14 2023-08-28

Related Actors

Related Reports

« Back