APT-C-55(Kimsuky)组织的RandomQuery窃密攻击活动分析
2024-03-15 • Qihoo360 • Analysis of RandomQuery secret stealing attack activities organized by APT-C-55 (Kimsuky) •
360 Advanced Threat Research Institute analyzes a RandomQuery espionage campaign attributed to APT-C-55, also known as Kimsuky. The attack begins with phishing emails that deliver a fake HTML file and RAR archive containing an LNK shortcut and decoy document, then uses VBS and PowerShell to pull additional scripts from attacker paths such as list.php and lib.php. The malware collects system details, running processes, recent Word files, directory listings, antivirus status, and browser data from Chrome, Edge, and Naver Whale, then encrypts and uploads the results to show.php. The focus on Naver Whale, shared infrastructure with earlier reporting, and the multi-stage information stealing chain support the source's Kimsuky attribution and Korean targeting assessment.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 165.154.230.24 | 2023-11-09 | 2024-04-17 |
| HASH | 54a11842db77475f2aaab5b2dc8a9319 | 2024-03-15 | 2024-03-15 |
| HASH | 67b455be12537a9195b4d614f3d5ac1b | 2024-03-15 | 2024-03-15 |
| HASH | cb9ee0593e822f36a75e428fe9018483 | 2024-03-15 | 2024-03-15 |
| URL | http://ba-reum.co.kr/adm/status… | 2024-03-15 | 2024-03-15 |
| URL | http://ba-reum.co.kr/adm/status… | 2024-03-15 | 2024-03-15 |
| URL | http://ba-reum.co.kr/adm/status… | 2024-03-15 | 2024-03-15 |
| URL | http://ba-reum.co.kr/adm/status… | 2024-03-15 | 2024-03-15 |
| URL | http://ba-reum.co.kr/adm/status… | 2024-03-15 | 2024-03-15 |
| URL | http://ba-reum.co.kr/adm/status… | 2024-03-15 | 2024-03-15 |
| DOMAIN | ba-reum.co.kr | 2023-10-30 | 2024-03-15 |