Detailed Analysis of AlphaSeed, a new version of Kimsuky’s AppleSeed written in Golang
2023-05-17 • S2W •
S2W TALON analyzed AlphaSeed, a suspected Kimsuky malware family found on VirusTotal in May 2023 and named from the internal path E:/Go_Project/src/alpha/naver_crawl_spy/. The sample is assessed with high confidence as a Go implementation related to AppleSeed because it shares file-encryption behavior, mail-sending threads, mailbox naming, and Kimsuky's prior use of Naver mail command channels such as NavRAT. AlphaSeed copies itself into %USERPROFILE%\.edge, persists through an HKCU Run value using regsvr32, collects keystrokes and screenshots, and exchanges commands and stolen data through Naver Mail using chromedp and cookie-based login rather than embedded credentials. The command flow uses RSA and RC4 to decrypt tasking from a Cmd mailbox and exfiltrates victim metadata and collected data through mail subjects/mailboxes, showing Kimsuky's continued migration of espionage tooling into Go and webmail-based C2.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 37ea9dba7ab6465f4d82c1af38a2733… | 2023-05-17 | 2023-05-17 |
| HASH | 5aa1cc14a82db34269de7778536c893… | 2023-05-17 | 2023-05-17 |
| HASH | 98916e83b272f5ead73412a5765e1cf… | 2023-05-17 | 2023-05-17 |
| HASH | f28d5ccdc79b0fcc02be021435252f4… | 2023-05-17 | 2023-05-17 |
| HASH | 57b248d18b9ee4106a5922a25eb03f7… | 2023-05-17 | 2023-05-17 |
| HASH | eb55211ca3b233555397cecf32ac0a8… | 2023-05-17 | 2023-05-17 |
| HASH | f78b3c0ccaa02b4b159b36557f6b99a… | 2023-05-17 | 2023-05-17 |
| HASH | 60308fa05380f183bf76f2acfbe8e145 | 2023-05-17 | 2023-05-17 |