Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems

2018-02-02 Mcafee

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/

McAfee ATR found Gold Dragon, Brave Prince, Ghost419, and Running Rat implants used alongside the 2018 Olympics-themed intrusion activity to establish persistence, profile victims, and enable continued data theft or follow-on access. Gold Dragon acted as a reconnaissance and downloader implant: it collected desktop, recent-file, program-folder, system, registry, and user-profile data, encrypted the results, and posted them to ink.inkboom.co.kr while also requesting next-stage payloads by computer name and username. The malware used Korean-specific tradecraft, including checking for the Hangul Word Processor process, extracting an embedded executable from an HWP file marker, and writing viso.exe into the user Startup folder for persistence. Infrastructure and overlap with earlier implants included ink.inkboom.co.kr, nid-help-pchange.atwebpages.com, and code/behavior shared with Brave Prince and Ghost419, while later activity reused hacked servers in Santiago, Chile. The activity matters because it shows the Olympics intrusion moving beyond initial PowerShell staging into durable endpoint access, victim profiling, and modular payload delivery.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN 000webhostapp.com 2018-02-02 2025-06-09
HASH 3a0c617d17e7f819775e48f7edefe9a… 2018-02-02 2020-03-09
HASH 4f58e6a7a04be2b2ecbcdcbae6f2817… 2018-02-02 2020-03-09
HASH e68f43ecb03330ff0420047b6193358… 2018-02-02 2020-03-09
HASH 11a38a9d23193d9582d02ab0eae767c… 2018-02-02 2020-03-09
HASH bf21667e4b48b8857020ba455531c9c… 2018-02-02 2020-03-09
DOMAIN ink.inkboom.co.kr 2018-02-02 2018-02-12
DOMAIN followgho.byethost7.com 2018-02-02 2018-02-12
HASH 465d48ae849bbd6505263f3323e818c… 2018-02-02 2018-02-02
HASH a9eb9a1734bb84bbc60df38d4a1e02a… 2018-02-02 2018-02-02
HASH ad08a60dc511d9b69e584c1310dbd60… 2018-02-02 2018-02-02
HASH fef671c13039df24e1606d5fdc65c92… 2018-02-02 2018-02-02
HASH 96a2fda8f26018724c86b275fe9396e… 2018-02-02 2018-02-02
HASH c2f01355880cd9dfeef75cff189f4a8… 2018-02-02 2018-02-02
HASH 35e5310b6183469f4995b7cd4f795da… 2018-02-02 2018-02-02
HASH 7e74f034d8aa4570bd1b7dcfcdfaa52… 2018-02-02 2018-02-02
HASH 5e1326dd7122e2e2aed04ca4de180d1… 2018-02-02 2018-02-02
HASH 5a7fdfa88addb88680c2f0d5f709522… 2018-02-02 2018-02-02
HASH 615447f458463dc77f7ae3b0a4ad20c… 2018-02-02 2018-02-02
HASH 06948ab527ae415f32ed4b0f0d70be4… 2018-02-02 2018-02-02
HASH 83706ddaa5ea5ee2cfff54b7c809458… 2018-02-02 2018-02-02
HASH 389db34c3a37fd288e92463302629aa… 2018-02-02 2018-02-02
HASH 539acd9145befd7e670fe826c248766… 2018-02-02 2018-02-02
HASH bc6cb78e20cb20285149d55563f6fdc… 2018-02-02 2018-02-02
HASH 7ae731d666e547b4f3442fe5675c8e8… 2018-02-02 2018-02-02
HASH 71f337dc65459027f4ab26198270368… 2018-02-02 2018-02-02
HASH 6e13875449beb00884e07a38d0dd2a7… 2018-02-02 2018-02-02
HASH 761b0690cd86fb472738b6dc32661ac… 2018-02-02 2018-02-02
HASH d63c7d7305a8b2184fff3b0941e596f… 2018-02-02 2018-02-02
URL https://minibodegaslock.cl/comp… 2018-02-02 2018-02-02
URL https://minibodegaslock.cl:443/… 2018-02-02 2018-02-02
URL http://inkdotinkboom.co.kr/host… 2018-02-02 2018-02-02
DOMAIN trydai.000webhostapp.com 2018-02-02 2018-02-02
DOMAIN eodo1.000webhostapp.com 2018-02-02 2018-02-02
DOMAIN nid-help-pchange.atwebpages.com 2018-02-02 2018-02-02
DOMAIN braveprince.com 2018-02-02 2018-02-02
DOMAIN inkdotinkboom.co.kr 2018-02-02 2018-02-02
DOMAIN minibodegaslock.cl 2018-02-02 2018-02-02
IPv4 223.194.70.136 2018-02-02 2018-02-02
IPv4 200.200.200.13 2018-02-02 2018-02-02

Related Reports

« Back