APT-C-55(Kimsuky)组织基于VMP强壳的HappyDoor后门攻击分析

2025-07-08 Qihoo360 Analysis of APT-C-55 (Kimsuky) HappyDoor Backdoor Attacks Using VMP Protection

https://mp.weixin.qq.com/s/fDan8ihUQEAF5Kf_6fXATQ

Thumbnail for APT-C-55(Kimsuky)组织基于VMP强壳的HappyDoor后门攻击分析

360 Advanced Threat Research Institute attributes a recent South Korea-focused intrusion to APT-C-55/Kimsuky, delivered through a trojanized Bandizip installer that installs the legitimate Korean Bandizip binary while launching malicious components in the background. The infection chain uses regsvr32 to load a dropped DLL, mshta to fetch obfuscated VBScript from 67.217.62[.]222, staged scripts to collect host, network, antivirus, and file-path data, and hidden scheduled-task persistence under ProgramData. The final payload is a VMProtect-packed HappyDoor backdoor, ut_happy(x64).dll, which copies itself under AppData, stores configuration and C2 data in registry keys, and supports multiple information-stealing and remote-control functions. Reported infrastructure includes u.appw.p-e[.]kr, d.appz.p-e[.]kr, mrasis.n-e[.]kr, and 67.217.62[.]222, with hashes for the Bandizip-themed installer and related payloads. The activity matters because it shows Kimsuky continuing to refine social-engineering delivery and analysis-evasion around a known backdoor family used for espionage against Korean targets.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN appw.p-e.kr 2025-07-08 2025-08-07
URL http://u.appw.p-e.kr/index.php 2025-07-08 2025-08-07
URL http://d.appz.p-e.kr/index.php 2025-07-08 2025-08-07
DOMAIN u.appw.p-e.kr 2025-07-08 2025-08-07
DOMAIN d.appz.p-e.kr 2025-07-08 2025-08-07
IPv4 67.217.62.222 2025-07-08 2025-08-07
HASH 07fbf46d3a595a6f82e477ed4571294b 2025-07-08 2025-07-08
HASH d1ec20144c83bba921243e72c517da5e 2025-07-08 2025-07-08
HASH f4cd4449e556b0580c2282fec1ca661f 2025-07-08 2025-07-08
HASH 16d30316a6b700c78d021df5758db775 2025-07-08 2025-07-08
URL http://mrasis.n-e.kr/comarov/se… 2025-03-19 2025-07-08
HASH a6598bbdc947286c84f951289d14425c 2025-03-17 2025-07-08
DOMAIN mrasis.n-e.kr 2025-03-17 2025-07-08

Related Actors

Related Reports

« Back