Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems
2018-02-02 • Mcafee •
McAfee ATR found Gold Dragon, Brave Prince, Ghost419, and Running Rat implants used alongside the 2018 Olympics-themed intrusion activity to establish persistence, profile victims, and enable continued data theft or follow-on access. Gold Dragon acted as a reconnaissance and downloader implant: it collected desktop, recent-file, program-folder, system, registry, and user-profile data, encrypted the results, and posted them to ink.inkboom.co.kr while also requesting next-stage payloads by computer name and username. The malware used Korean-specific tradecraft, including checking for the Hangul Word Processor process, extracting an embedded executable from an HWP file marker, and writing viso.exe into the user Startup folder for persistence. Infrastructure and overlap with earlier implants included ink.inkboom.co.kr, nid-help-pchange.atwebpages.com, and code/behavior shared with Brave Prince and Ghost419, while later activity reused hacked servers in Santiago, Chile. The activity matters because it shows the Olympics intrusion moving beyond initial PowerShell staging into durable endpoint access, victim profiling, and modular payload delivery.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | 000webhostapp.com | 2018-02-02 | 2025-06-09 |
| HASH | 3a0c617d17e7f819775e48f7edefe9a… | 2018-02-02 | 2020-03-09 |
| HASH | 4f58e6a7a04be2b2ecbcdcbae6f2817… | 2018-02-02 | 2020-03-09 |
| HASH | e68f43ecb03330ff0420047b6193358… | 2018-02-02 | 2020-03-09 |
| HASH | 11a38a9d23193d9582d02ab0eae767c… | 2018-02-02 | 2020-03-09 |
| HASH | bf21667e4b48b8857020ba455531c9c… | 2018-02-02 | 2020-03-09 |
| DOMAIN | ink.inkboom.co.kr | 2018-02-02 | 2018-02-12 |
| DOMAIN | followgho.byethost7.com | 2018-02-02 | 2018-02-12 |
| HASH | 465d48ae849bbd6505263f3323e818c… | 2018-02-02 | 2018-02-02 |
| HASH | a9eb9a1734bb84bbc60df38d4a1e02a… | 2018-02-02 | 2018-02-02 |
| HASH | ad08a60dc511d9b69e584c1310dbd60… | 2018-02-02 | 2018-02-02 |
| HASH | fef671c13039df24e1606d5fdc65c92… | 2018-02-02 | 2018-02-02 |
| HASH | 96a2fda8f26018724c86b275fe9396e… | 2018-02-02 | 2018-02-02 |
| HASH | c2f01355880cd9dfeef75cff189f4a8… | 2018-02-02 | 2018-02-02 |
| HASH | 35e5310b6183469f4995b7cd4f795da… | 2018-02-02 | 2018-02-02 |
| HASH | 7e74f034d8aa4570bd1b7dcfcdfaa52… | 2018-02-02 | 2018-02-02 |
| HASH | 5e1326dd7122e2e2aed04ca4de180d1… | 2018-02-02 | 2018-02-02 |
| HASH | 5a7fdfa88addb88680c2f0d5f709522… | 2018-02-02 | 2018-02-02 |
| HASH | 615447f458463dc77f7ae3b0a4ad20c… | 2018-02-02 | 2018-02-02 |
| HASH | 06948ab527ae415f32ed4b0f0d70be4… | 2018-02-02 | 2018-02-02 |
| HASH | 83706ddaa5ea5ee2cfff54b7c809458… | 2018-02-02 | 2018-02-02 |
| HASH | 389db34c3a37fd288e92463302629aa… | 2018-02-02 | 2018-02-02 |
| HASH | 539acd9145befd7e670fe826c248766… | 2018-02-02 | 2018-02-02 |
| HASH | bc6cb78e20cb20285149d55563f6fdc… | 2018-02-02 | 2018-02-02 |
| HASH | 7ae731d666e547b4f3442fe5675c8e8… | 2018-02-02 | 2018-02-02 |
| HASH | 71f337dc65459027f4ab26198270368… | 2018-02-02 | 2018-02-02 |
| HASH | 6e13875449beb00884e07a38d0dd2a7… | 2018-02-02 | 2018-02-02 |
| HASH | 761b0690cd86fb472738b6dc32661ac… | 2018-02-02 | 2018-02-02 |
| HASH | d63c7d7305a8b2184fff3b0941e596f… | 2018-02-02 | 2018-02-02 |
| URL | https://minibodegaslock.cl/comp… | 2018-02-02 | 2018-02-02 |
| URL | https://minibodegaslock.cl:443/… | 2018-02-02 | 2018-02-02 |
| URL | http://inkdotinkboom.co.kr/host… | 2018-02-02 | 2018-02-02 |
| DOMAIN | trydai.000webhostapp.com | 2018-02-02 | 2018-02-02 |
| DOMAIN | eodo1.000webhostapp.com | 2018-02-02 | 2018-02-02 |
| DOMAIN | nid-help-pchange.atwebpages.com | 2018-02-02 | 2018-02-02 |
| DOMAIN | braveprince.com | 2018-02-02 | 2018-02-02 |
| DOMAIN | inkdotinkboom.co.kr | 2018-02-02 | 2018-02-02 |
| DOMAIN | minibodegaslock.cl | 2018-02-02 | 2018-02-02 |
| IPv4 | 223.194.70.136 | 2018-02-02 | 2018-02-02 |
| IPv4 | 200.200.200.13 | 2018-02-02 | 2018-02-02 |