Hermit(隐士):针对朝鲜半岛的APT攻击活动披露

2018-12-20 Tencent Hermit: APT attack campaign targeting the Korean Peninsula disclosed

https://s.tencent.com/research/report/613.html

Thumbnail for Hermit(隐士):针对朝鲜半岛的APT攻击活动披露

Tencent’s threat-intelligence report disclosed Hermit, a spear-phishing campaign against Korean Peninsula-related targets that the researchers linked to the same organization behind SYSCON/SANNY and KONNI activity. The malicious documents required macro execution and used certutil to download and decode a staged batch script from `filer2.1apps.com`, then selected x86 or x64 CAB payloads containing persistence logic, a UAC-bypass module, encrypted C2 configuration, and the BrowserUpdate.exe backdoor. The core payload decrypted shellcode, reconstructed and loaded a PE file in memory, connected to a C2 server, and supported directory listing, upload, download, file execution, process listing, and process termination. Tencent also described a second-stage hidden TeamViewer variant (`iiexplorer.exe`) used for remote control, linked the codebase to the older Babyface RAT source, and published hashes plus C2 `103.249.31.159:7777`.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a25811b24b7f27a486c05c0a09ad992d 2018-12-20 2019-08-29
IPv4 103.249.31.159 2018-12-20 2019-08-29
HASH 0eb6090397c74327cd4d47819f724953 2018-12-20 2019-06-10
HASH 2bfbf8ce47585aa86b1ab90ff109fd57 2018-12-20 2019-06-10
DOMAIN filer2.1apps.com 2018-12-20 2019-06-10
DOMAIN gmall.com 2018-09-06 2019-06-10
HASH ff8f9a20c00d9d41836bfa4fac3244a9 2018-12-20 2018-12-20
HASH 1dcaf6c62c65b4594a27259bd8bc31ea 2018-12-20 2018-12-20
HASH 25dd8c4965b09df082968ad4f92ffe5f 2018-12-20 2018-12-20
HASH 7f7b32771da9760a9e233807196f086d 2018-12-20 2018-12-20
HASH 7090eb434f228705acd8d2da5e7c7899 2018-12-20 2018-12-20
HASH 282f3f17d7d6dc68e220fe328adc66c5 2018-12-20 2018-12-20
HASH fcceef71738e1506c4524e3210f4b23d 2018-12-20 2018-12-20
HASH c9f0125b449dd44d112644901d787e3f 2018-12-20 2018-12-20
HASH 38b3045a69ff6339adec25822d4d8e25 2018-12-20 2018-12-20
EMAIL [email protected] 2018-12-20 2018-12-20
EMAIL [email protected] 2018-12-20 2018-12-20
URL http://www.pudn.com/Download/it… 2018-12-20 2018-12-20
URL http://filer2.1apps.com/1.txt 2018-12-20 2018-12-20

Related Actors

Related Reports

« Back