Fake AV Investigation Unearths KevDroid, New Android Malware

2018-04-02 Cisco Talos

http://blog.talosintelligence.com/2018/04/fake-av-investigation-unearths-kevdroid.html

Thumbnail for Fake AV Investigation Unearths KevDroid, New Android Malware

Cisco Talos investigated KevDroid after a reported possible Group 123 connection, but concluded the observed overlaps were too weak to establish a real link. The Android RAT variants stole device data such as contacts, SMS, call history, location, and phone-call recordings, with one variant attempting Android privilege escalation via CVE-2015-3636. The same infrastructure hosted Windows malware, including PubNubRAT, which used PubNub as command-and-control to receive orders, steal files, execute commands, kill processes, download files, and take screenshots. The Windows infection chain included a Korean-language RTF lure about Bitcoin and China that exploited CVE-2017-11882 to download and execute a hosted payload. The report matters for DPRK-focused tracking chiefly because it evaluates and rejects strong Group 123 attribution while documenting mobile and Windows espionage tooling targeting Korean users.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ps.pndsn.com 2018-04-02 2020-03-25
HASH 90abfe3e4f21b5a16cd1ff3c485f079… 2018-04-02 2020-03-09
URL http://ebsmpi.com/ipin/360/desk… 2018-04-02 2018-08-22
URL http://ebsmpi.com/ipin/360/Ant_… 2018-04-02 2018-08-22
URL http://cgalim.com/admin/hr/1.apk 2018-04-02 2018-08-22
URL http://cgalim.com/admin/hr/hr.d… 2018-04-02 2018-08-22
URL http://ebsmpi.com/ipin/360/Ant_… 2018-04-02 2018-08-22
DOMAIN ebsmpi.com 2018-04-02 2018-08-22
DOMAIN cgalim.com 2018-04-02 2018-08-22
HASH 6b1f2dfe805fa0e27139c5a48400425… 2018-04-02 2018-04-05
HASH f33aedfe5ebc918f5489e1f8a9fe19b… 2018-04-02 2018-04-05
HASH 86887ce368d9a3e7fdf9aa62418cd68… 2018-04-02 2018-04-05
HASH dd3f5ad44a80e7872e826869d270cbd… 2018-04-02 2018-04-02
HASH 7a82cc0330e8974545d5a8cdca95b8d… 2018-04-02 2018-04-02
HASH c015292aab1d41acd0674c98cd8e913… 2018-04-02 2018-04-02
HASH d24d1b667829db9871080b97516dbe2… 2018-04-02 2018-04-02
HASH 9ff7240c77fca939cde0eb1ffe7f642… 2018-04-02 2018-04-02
HASH 4cb16189f52a428a49916a8b533fdeb… 2018-04-02 2018-04-02
URL http://cgalim.com/admin/1211me/… 2018-04-02 2018-04-02
URL http://cgalim.com/admin/1211me/… 2018-04-02 2018-04-02
URL http://cgalim.com/admin/hr/pu/p… 2018-04-02 2018-04-02
URL http://cgalim.com/admin/1211me/… 2018-04-02 2018-04-02

Related Actors

Related Reports

« Back