DPRK Targeting Researchers II: .Sys Payload and Registry Hunting
2021-02-01 • Norfolk •
https://norfolkinfosec.com/dprk-targeting-researchers-ii-sys-payload-and-registry-hunting/
Norfolk Infosec analyzed a malicious helpsvc.sys component from a DPRK-affiliated campaign targeting security researchers, likely delivered through a watering-hole route rather than the earlier Visual Studio social-engineering chain. The file behaves like a service DLL and attempts to read hidden payload data from HKLM\Software\Microsoft\Windows\CurrentVersion\KernelConfig values named SubVersion and Description. Recovered registry data enabled a second-stage executable to run, dynamically resolve Windows APIs, communicate with C2 servers over OpenSSL, and store data under HKLM\Software\Microsoft\Windows\CurrentVersion\DriverConfig. The decoded C2 endpoints included colasprint.com, dronerc.it, and fabioluciani.com paths, and the command set supported file execution, process and directory enumeration, network-adapter collection, drive and file discovery, process control, and screen capture. The registry-resident payload design gives defenders a hunting angle around unusually large registry values used to stage executable code.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3b3acb4a55ba8e2da36223ae59ed420… | 2021-02-01 | 2021-02-01 |
| HASH | 79bd808e03ed03821b6d72dd8246995… | 2021-02-01 | 2021-02-01 |
| HASH | ae17ce1eb59dd82f38efb9666f279044 | 2021-02-01 | 2021-02-01 |
| HASH | 7c4ea495f9145bd9bdc3f9f084053a6… | 2021-02-01 | 2021-02-01 |
| HASH | 7904d5ee5700c126432a0b4dab2776c9 | 2021-02-01 | 2021-02-01 |
| HASH | a4fb20b15efd72f983f0fb3325c0352… | 2021-01-25 | 2021-02-01 |