BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat

2019-04-26 Paloalto Networks

https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/

Thumbnail for BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat

Unit 42 reports that BabyShark activity continued through March and April 2019 after earlier spear-phishing against U.S. national-security think tanks, with newer decoys also showing interest in cryptocurrency-related financial gain. The malware used a multi-stage structure with server-side checks, base64-encoded denylisted IPs and computer names in blackip.txt, suspicious-access logging, and redirects to go.microsoft.com to hide exposed C2 files. Operators could issue VBS and PowerShell commands to archive and upload files, collect host information, run keyloggers, load DLLs, execute secondary payloads, and clean up execution artifacts. The researchers recovered server and client files showing that BabyShark delivered encoded “Cowboy” payloads through EXE or DLL loaders, with KimJongRAT and PCRat observed as the secondary malware families.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4b3416fb6d1ed1f762772b4dd4f4f65… 2019-04-26 2020-03-09
HASH bd6efb16527b025a5fd256bb357a91b… 2019-04-26 2020-03-09
HASH d742aa65c4880f85ae43feebb0781b67 2019-04-26 2019-04-26
HASH d50a0980da6297b8e4cec5db0a87736… 2019-04-26 2019-04-26
HASH 33ce9bcaeb0733a77ff0d85263ce035… 2019-04-26 2019-04-26
HASH 75917cc1bd9ecd7ef57b7ef42810777… 2019-04-26 2019-04-26
HASH bde663d08d4e2e17940d890ccf2e6e74 2019-04-26 2019-04-26
HASH f86d05c1d7853c06fc5561f8df19b53… 2019-04-26 2019-04-26
HASH daab894b81cc375f0684ae66981b357d 2019-04-26 2019-04-26
IPv4 173.248.170.149 2018-12-05 2019-04-26

Related Reports

« Back