Bisonal Malware Used in Attacks Against Russia and South Korea
2018-07-31 • Paloalto Networks •
Unit 42 identified a Bisonal campaign that targeted at least one Russian defense-related communications security company and one unidentified South Korean organization in early May 2018. The attackers used spear-phishing with a Windows executable disguised as a PDF and displayed a Rostec housing-project decoy to make the lure credible to the Russian victim. The dropper decrypted an embedded Bisonal DLL and decoy file with the RC4 key "34123412," wrote them under Windows Temp, and configured Run-key persistence through rundll32. The excerpt also notes common Bisonal tradecraft—government, military, and defense targets in South Korea, Russia, and Japan; occasional DDNS C2; target or campaign codes; and decoy documents—making the campaign useful for hunting related Bisonal activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0641fe04713fbdad272a6f8e9b44631… | 2018-07-31 | 2018-07-31 |
| HASH | f431e0bed6b4b7ffef5e40b1b4b7078… | 2018-07-31 | 2018-07-31 |
| HASH | b1da7e1963dc09c325ba3ea2442a54a… | 2018-07-31 | 2018-07-31 |
| HASH | 359835c4a9dbe2d95e4834646597444… | 2018-07-31 | 2018-07-31 |
| HASH | b2b764597d097fcb93c5b11cbd864ab… | 2018-07-31 | 2018-07-31 |
| HASH | dfa1ad6083aa06b82edfa672925bb78… | 2018-07-31 | 2018-07-31 |
| HASH | 43459f5117bee7b49f2cee7ce934471… | 2018-07-31 | 2018-07-31 |
| HASH | 1128d10347dd602ecd3228faa389add… | 2018-07-31 | 2018-07-31 |
| DOMAIN | kted56erhg.dynssl.com | 2018-07-31 | 2018-07-31 |
| DOMAIN | games.my-homeip.com | 2018-07-31 | 2018-07-31 |
| DOMAIN | euiro8966.organiccrap.com | 2018-07-31 | 2018-07-31 |
| IPv4 | 196.44.49.154 | 2018-07-31 | 2018-07-31 |
| IPv4 | 116.193.155.38 | 2018-07-31 | 2018-07-31 |