APT43 배후의 다단계 드롭박스 명령과 TutorialRAT

2024-04-17 Genians APT43 behind multi-stage Dropbox commands and TutorialRAT

https://www.genians.co.kr/blog/threat_intelligence/dropbox

Thumbnail for APT43 배후의 다단계 드롭박스 명령과 TutorialRAT

APT43 is reported using a multi-stage attack chain that abuses Dropbox cloud storage and deploys TutorialRAT as part of activity linked to the BabyShark campaign lineage. The source highlights lures impersonating policy meetings, advisory sessions, surveys, and lecture notices, with an initial approach through normal email followed by responsive spear-phishing tactics. Use of a legitimate cloud service as attack infrastructure can reduce visibility for defenders who monitor only obviously malicious hosting, while the RAT stage creates endpoint detection opportunities. Security teams should review the archive for email lure patterns, Dropbox-based staging, TutorialRAT behavior, and telemetry that can separate legitimate cloud use from adversary operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b9898e8e5b6494bcc219462c6be7c248 2024-04-17 2024-06-12
HASH d19253d84c6cb8fb6064e6d33bed556f 2024-04-17 2024-06-12
HASH 0040f03faf5bbdc555f2039a4e33a82b 2024-01-30 2024-06-12
HASH 61a30992e0a7ab93cd3a47cc51284b35 2024-04-17 2024-04-17
HASH f395012ff30a846d0e7ed787147f5723 2024-04-17 2024-04-17
HASH 544963f602ec6c97994d38ce39368d79 2024-04-17 2024-04-17
HASH ade1d12604dd9d62f6ef97a93cda142b 2024-04-17 2024-04-17
HASH 781acd3a8250da862e48425d078b54ad 2024-04-17 2024-04-17
HASH 2f9125a538d84dd952f72722f28575b8 2024-04-17 2024-04-17
HASH 5ad5ace1ec82538f66acf13e48cf8db4 2024-04-17 2024-04-17
HASH 515194ef77fbbe04845de290eefd0049 2024-04-17 2024-04-17
HASH a9276bae977589f3f670f26b2cb8a9f1 2024-04-17 2024-04-17
DOMAIN meatalk.com 2024-04-17 2024-04-17
DOMAIN iso3488.co.kr 2024-04-17 2024-04-17
DOMAIN strehab.com 2024-04-17 2024-04-17
DOMAIN kyungdaek.com 2024-04-17 2024-04-17
DOMAIN siloamclinic.com 2024-04-17 2024-04-17
DOMAIN aymdtt.co.kr 2024-04-17 2024-04-17
DOMAIN vwellpain.com 2024-04-17 2024-04-17
IPv4 183.111.141.93 2024-04-17 2024-04-17
HASH a4bd6d00abbd79ab00161ff538cfe703 2024-04-03 2024-04-17
HASH eb08ab3854168c834ab154facfe695a3 2024-03-22 2024-04-17
HASH 1e66ac680d0edfe18d97b89e46c7e82e 2024-03-22 2024-04-17
HASH c700195f61635b9a6fb1ee4359b91940 2024-03-22 2024-04-17
DOMAIN regard.co.kr 2024-03-18 2024-04-17
HASH 3e3013fe03f7416b8d1e96591f8e5839 2024-01-30 2024-04-17
HASH fcdcc6c56ae43f7a78413cc5204e9314 2024-01-30 2024-04-17
HASH 32519b46b55792084240f850e0c94298 2024-01-30 2024-04-17
DOMAIN gbionet.com 2024-01-30 2024-04-17
IPv4 122.155.191.33 2024-01-30 2024-04-17
HASH dce864eabfbd6445682a4671a2fee1a9 2023-12-29 2024-04-17
DOMAIN dddon.kr 2023-12-29 2024-04-17
HASH 64dee04b6e6404c14d10971adf35c3a7 2023-11-09 2024-04-17
HASH eb614c99614c3365bdc926a73ef7a492 2023-11-09 2024-04-17
HASH fb5aec165279015f17b29f9f2c730976 2023-11-09 2024-04-17
HASH b70bc31b537caf411f97a991d8292c5a 2023-11-09 2024-04-17
IPv4 165.154.230.24 2023-11-09 2024-04-17
IPv4 218.150.78.197 2023-09-26 2024-04-17
HASH 8133c5f663f89b01b30a052749b5a988 2023-06-16 2024-04-17
DOMAIN well-story.co.kr 2023-06-16 2024-04-17

Related Actors

Related Reports

« Back