DPRK Targeting Researchers II: .Sys Payload and Registry Hunting

2021-02-01 Norfolk

https://norfolkinfosec.com/dprk-targeting-researchers-ii-sys-payload-and-registry-hunting/

Thumbnail for DPRK Targeting Researchers II: .Sys Payload and Registry Hunting

Norfolk Infosec analyzed a malicious helpsvc.sys component from a DPRK-affiliated campaign targeting security researchers, likely delivered through a watering-hole route rather than the earlier Visual Studio social-engineering chain. The file behaves like a service DLL and attempts to read hidden payload data from HKLM\Software\Microsoft\Windows\CurrentVersion\KernelConfig values named SubVersion and Description. Recovered registry data enabled a second-stage executable to run, dynamically resolve Windows APIs, communicate with C2 servers over OpenSSL, and store data under HKLM\Software\Microsoft\Windows\CurrentVersion\DriverConfig. The decoded C2 endpoints included colasprint.com, dronerc.it, and fabioluciani.com paths, and the command set supported file execution, process and directory enumeration, network-adapter collection, drive and file discovery, process control, and screen capture. The registry-resident payload design gives defenders a hunting angle around unusually large registry values used to stage executable code.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3b3acb4a55ba8e2da36223ae59ed420… 2021-02-01 2021-02-01
HASH 79bd808e03ed03821b6d72dd8246995… 2021-02-01 2021-02-01
HASH ae17ce1eb59dd82f38efb9666f279044 2021-02-01 2021-02-01
HASH 7c4ea495f9145bd9bdc3f9f084053a6… 2021-02-01 2021-02-01
HASH 7904d5ee5700c126432a0b4dab2776c9 2021-02-01 2021-02-01
HASH a4fb20b15efd72f983f0fb3325c0352… 2021-01-25 2021-02-01

Related Reports

« Back