CJ Olivenetworks 인증서 악용 악성코드 분석 : 유출된 인증서를 악용한 Kimsuky 그룹의 피싱 캠페인
2025-05-30 • Igloo • Cyber threat report on Kimsuky, CJOliveNetworks •
https://www.igloopedia.com/1f5f216a-760c-80c0-a6e3-e07e401caf23
IGLOO links a CJ Olivenetworks certificate-abuse malware sample to Kimsuky based on tradecraft overlap with an earlier Nexaweb certificate-abuse phishing campaign, including a Go-built dropper, Acrobat-like icon, and a backdoor internally named httpSpy.dll. The dropper appears to have been delivered in a spear-phishing RAR and used a screen-saver executable disguised as a document, creating a decoy PDF tied to a Korea Institute of Machinery and Materials IP access request. After execution, it deletes itself, drops an unsigned DLL as config.dat under the public user directory, and runs its exported function with rundll32.exe. The backdoor uses VMProtect-like obfuscation, decrypts strings and APIs dynamically, establishes persistence via registry or service mechanisms, stores configuration with NTFS alternate data streams, and attempts HTTP C2 communication with gsegse.dasfesfgsegsefsede.o-r.kr. The abuse of a timestamped leaked certificate matters because it can preserve apparent signature validity even after revocation, increasing trust from users and security controls.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://gsegse.dasfesfgsegsefsed… | 2025-05-19 | 2026-04-07 |
| DOMAIN | gsegse.dasfesfgsegsefsede.o-r.kr | 2025-05-15 | 2026-04-07 |
| HASH | 537806c02659a12c5b21efa51b2322c1 | 2024-06-07 | 2025-06-09 |
| HASH | c05022f6827c6c99b21f01a44c704a25 | 2025-05-30 | 2025-05-30 |
| HASH | 01e349800e4c04fd58f7d20c52e12daa | 2025-05-30 | 2025-05-30 |
| URL | http://gsegse.dasfesfgsegsefsed… | 2025-05-30 | 2025-05-30 |
| HASH | 7ec88818697623a0130b1de42fa31335 | 2025-05-15 | 2025-05-30 |
| HASH | 580d7a5fdf78dd3e720b2ce772dc77e9 | 2025-05-15 | 2025-05-30 |
| HASH | aa8936431f7bc0fabb0b9efb6ea153f9 | 2024-06-19 | 2025-05-30 |