APT-C-55(Kimsuky)组织的RandomQuery窃密攻击活动分析

2024-03-15 Qihoo360 Analysis of RandomQuery secret stealing attack activities organized by APT-C-55 (Kimsuky)

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247495843&idx=1&sn=7965885f6dc8503c7fc49b7002816d13&chksm=f9c1c3aaceb64abcf4ee0b127600eed9c4013a3aaa1a7af7fb3d222b9264b365eed9fb475028&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-55(Kimsuky)组织的RandomQuery窃密攻击活动分析

360 Advanced Threat Research Institute analyzes a RandomQuery espionage campaign attributed to APT-C-55, also known as Kimsuky. The attack begins with phishing emails that deliver a fake HTML file and RAR archive containing an LNK shortcut and decoy document, then uses VBS and PowerShell to pull additional scripts from attacker paths such as list.php and lib.php. The malware collects system details, running processes, recent Word files, directory listings, antivirus status, and browser data from Chrome, Edge, and Naver Whale, then encrypts and uploads the results to show.php. The focus on Naver Whale, shared infrastructure with earlier reporting, and the multi-stage information stealing chain support the source's Kimsuky attribution and Korean targeting assessment.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 165.154.230.24 2023-11-09 2024-04-17
HASH 54a11842db77475f2aaab5b2dc8a9319 2024-03-15 2024-03-15
HASH 67b455be12537a9195b4d614f3d5ac1b 2024-03-15 2024-03-15
HASH cb9ee0593e822f36a75e428fe9018483 2024-03-15 2024-03-15
URL http://ba-reum.co.kr/adm/status… 2024-03-15 2024-03-15
URL http://ba-reum.co.kr/adm/status… 2024-03-15 2024-03-15
URL http://ba-reum.co.kr/adm/status… 2024-03-15 2024-03-15
URL http://ba-reum.co.kr/adm/status… 2024-03-15 2024-03-15
URL http://ba-reum.co.kr/adm/status… 2024-03-15 2024-03-15
URL http://ba-reum.co.kr/adm/status… 2024-03-15 2024-03-15
DOMAIN ba-reum.co.kr 2023-10-30 2024-03-15

Related Actors

Related Reports

« Back