APT-C-55(Kimsuky)组织基于VMP强壳的HappyDoor后门攻击分析
2025-07-08 • Qihoo360 • Analysis of APT-C-55 (Kimsuky) HappyDoor Backdoor Attacks Using VMP Protection •
360 Advanced Threat Research Institute attributes a recent South Korea-focused intrusion to APT-C-55/Kimsuky, delivered through a trojanized Bandizip installer that installs the legitimate Korean Bandizip binary while launching malicious components in the background. The infection chain uses regsvr32 to load a dropped DLL, mshta to fetch obfuscated VBScript from 67.217.62[.]222, staged scripts to collect host, network, antivirus, and file-path data, and hidden scheduled-task persistence under ProgramData. The final payload is a VMProtect-packed HappyDoor backdoor, ut_happy(x64).dll, which copies itself under AppData, stores configuration and C2 data in registry keys, and supports multiple information-stealing and remote-control functions. Reported infrastructure includes u.appw.p-e[.]kr, d.appz.p-e[.]kr, mrasis.n-e[.]kr, and 67.217.62[.]222, with hashes for the Bandizip-themed installer and related payloads. The activity matters because it shows Kimsuky continuing to refine social-engineering delivery and analysis-evasion around a known backdoor family used for espionage against Korean targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | appw.p-e.kr | 2025-07-08 | 2025-08-07 |
| URL | http://u.appw.p-e.kr/index.php | 2025-07-08 | 2025-08-07 |
| URL | http://d.appz.p-e.kr/index.php | 2025-07-08 | 2025-08-07 |
| DOMAIN | u.appw.p-e.kr | 2025-07-08 | 2025-08-07 |
| DOMAIN | d.appz.p-e.kr | 2025-07-08 | 2025-08-07 |
| IPv4 | 67.217.62.222 | 2025-07-08 | 2025-08-07 |
| HASH | 07fbf46d3a595a6f82e477ed4571294b | 2025-07-08 | 2025-07-08 |
| HASH | d1ec20144c83bba921243e72c517da5e | 2025-07-08 | 2025-07-08 |
| HASH | f4cd4449e556b0580c2282fec1ca661f | 2025-07-08 | 2025-07-08 |
| HASH | 16d30316a6b700c78d021df5758db775 | 2025-07-08 | 2025-07-08 |
| URL | http://mrasis.n-e.kr/comarov/se… | 2025-03-19 | 2025-07-08 |
| HASH | a6598bbdc947286c84f951289d14425c | 2025-03-17 | 2025-07-08 |
| DOMAIN | mrasis.n-e.kr | 2025-03-17 | 2025-07-08 |