Fake AV Investigation Unearths KevDroid, New Android Malware
2018-04-02 • Cisco Talos •
http://blog.talosintelligence.com/2018/04/fake-av-investigation-unearths-kevdroid.html
Cisco Talos investigated KevDroid after a reported possible Group 123 connection, but concluded the observed overlaps were too weak to establish a real link. The Android RAT variants stole device data such as contacts, SMS, call history, location, and phone-call recordings, with one variant attempting Android privilege escalation via CVE-2015-3636. The same infrastructure hosted Windows malware, including PubNubRAT, which used PubNub as command-and-control to receive orders, steal files, execute commands, kill processes, download files, and take screenshots. The Windows infection chain included a Korean-language RTF lure about Bitcoin and China that exploited CVE-2017-11882 to download and execute a hosted payload. The report matters for DPRK-focused tracking chiefly because it evaluates and rejects strong Group 123 attribution while documenting mobile and Windows espionage tooling targeting Korean users.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ps.pndsn.com | 2018-04-02 | 2020-03-25 |
| HASH | 90abfe3e4f21b5a16cd1ff3c485f079… | 2018-04-02 | 2020-03-09 |
| URL | http://ebsmpi.com/ipin/360/desk… | 2018-04-02 | 2018-08-22 |
| URL | http://ebsmpi.com/ipin/360/Ant_… | 2018-04-02 | 2018-08-22 |
| URL | http://cgalim.com/admin/hr/1.apk | 2018-04-02 | 2018-08-22 |
| URL | http://cgalim.com/admin/hr/hr.d… | 2018-04-02 | 2018-08-22 |
| URL | http://ebsmpi.com/ipin/360/Ant_… | 2018-04-02 | 2018-08-22 |
| DOMAIN | ebsmpi.com | 2018-04-02 | 2018-08-22 |
| DOMAIN | cgalim.com | 2018-04-02 | 2018-08-22 |
| HASH | 6b1f2dfe805fa0e27139c5a48400425… | 2018-04-02 | 2018-04-05 |
| HASH | f33aedfe5ebc918f5489e1f8a9fe19b… | 2018-04-02 | 2018-04-05 |
| HASH | 86887ce368d9a3e7fdf9aa62418cd68… | 2018-04-02 | 2018-04-05 |
| HASH | dd3f5ad44a80e7872e826869d270cbd… | 2018-04-02 | 2018-04-02 |
| HASH | 7a82cc0330e8974545d5a8cdca95b8d… | 2018-04-02 | 2018-04-02 |
| HASH | c015292aab1d41acd0674c98cd8e913… | 2018-04-02 | 2018-04-02 |
| HASH | d24d1b667829db9871080b97516dbe2… | 2018-04-02 | 2018-04-02 |
| HASH | 9ff7240c77fca939cde0eb1ffe7f642… | 2018-04-02 | 2018-04-02 |
| HASH | 4cb16189f52a428a49916a8b533fdeb… | 2018-04-02 | 2018-04-02 |
| URL | http://cgalim.com/admin/1211me/… | 2018-04-02 | 2018-04-02 |
| URL | http://cgalim.com/admin/1211me/… | 2018-04-02 | 2018-04-02 |
| URL | http://cgalim.com/admin/hr/pu/p… | 2018-04-02 | 2018-04-02 |
| URL | http://cgalim.com/admin/1211me/… | 2018-04-02 | 2018-04-02 |