CJ Olivenetworks 인증서 악용 악성코드 분석 : 유출된 인증서를 악용한 Kimsuky 그룹의 피싱 캠페인

2025-05-30 Igloo Cyber threat report on Kimsuky, CJOliveNetworks

https://www.igloopedia.com/1f5f216a-760c-80c0-a6e3-e07e401caf23

Thumbnail for CJ Olivenetworks 인증서 악용 악성코드 분석 : 유출된 인증서를 악용한 Kimsuky 그룹의 피싱 캠페인

IGLOO links a CJ Olivenetworks certificate-abuse malware sample to Kimsuky based on tradecraft overlap with an earlier Nexaweb certificate-abuse phishing campaign, including a Go-built dropper, Acrobat-like icon, and a backdoor internally named httpSpy.dll. The dropper appears to have been delivered in a spear-phishing RAR and used a screen-saver executable disguised as a document, creating a decoy PDF tied to a Korea Institute of Machinery and Materials IP access request. After execution, it deletes itself, drops an unsigned DLL as config.dat under the public user directory, and runs its exported function with rundll32.exe. The backdoor uses VMProtect-like obfuscation, decrypts strings and APIs dynamically, establishes persistence via registry or service mechanisms, stores configuration with NTFS alternate data streams, and attempts HTTP C2 communication with gsegse.dasfesfgsegsefsede.o-r.kr. The abuse of a timestamped leaked certificate matters because it can preserve apparent signature validity even after revocation, increasing trust from users and security controls.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://gsegse.dasfesfgsegsefsed… 2025-05-19 2026-04-07
DOMAIN gsegse.dasfesfgsegsefsede.o-r.kr 2025-05-15 2026-04-07
HASH 537806c02659a12c5b21efa51b2322c1 2024-06-07 2025-06-09
HASH c05022f6827c6c99b21f01a44c704a25 2025-05-30 2025-05-30
HASH 01e349800e4c04fd58f7d20c52e12daa 2025-05-30 2025-05-30
URL http://gsegse.dasfesfgsegsefsed… 2025-05-30 2025-05-30
HASH 7ec88818697623a0130b1de42fa31335 2025-05-15 2025-05-30
HASH 580d7a5fdf78dd3e720b2ce772dc77e9 2025-05-15 2025-05-30
HASH aa8936431f7bc0fabb0b9efb6ea153f9 2024-06-19 2025-05-30

Related Actors

Related Reports

« Back