Hermit(隐士):针对朝鲜半岛的APT攻击活动披露
2018-12-20 • Tencent • Hermit: APT attack campaign targeting the Korean Peninsula disclosed •
Tencent’s threat-intelligence report disclosed Hermit, a spear-phishing campaign against Korean Peninsula-related targets that the researchers linked to the same organization behind SYSCON/SANNY and KONNI activity. The malicious documents required macro execution and used certutil to download and decode a staged batch script from `filer2.1apps.com`, then selected x86 or x64 CAB payloads containing persistence logic, a UAC-bypass module, encrypted C2 configuration, and the BrowserUpdate.exe backdoor. The core payload decrypted shellcode, reconstructed and loaded a PE file in memory, connected to a C2 server, and supported directory listing, upload, download, file execution, process listing, and process termination. Tencent also described a second-stage hidden TeamViewer variant (`iiexplorer.exe`) used for remote control, linked the codebase to the older Babyface RAT source, and published hashes plus C2 `103.249.31.159:7777`.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a25811b24b7f27a486c05c0a09ad992d | 2018-12-20 | 2019-08-29 |
| IPv4 | 103.249.31.159 | 2018-12-20 | 2019-08-29 |
| HASH | 0eb6090397c74327cd4d47819f724953 | 2018-12-20 | 2019-06-10 |
| HASH | 2bfbf8ce47585aa86b1ab90ff109fd57 | 2018-12-20 | 2019-06-10 |
| DOMAIN | filer2.1apps.com | 2018-12-20 | 2019-06-10 |
| DOMAIN | gmall.com | 2018-09-06 | 2019-06-10 |
| HASH | ff8f9a20c00d9d41836bfa4fac3244a9 | 2018-12-20 | 2018-12-20 |
| HASH | 1dcaf6c62c65b4594a27259bd8bc31ea | 2018-12-20 | 2018-12-20 |
| HASH | 25dd8c4965b09df082968ad4f92ffe5f | 2018-12-20 | 2018-12-20 |
| HASH | 7f7b32771da9760a9e233807196f086d | 2018-12-20 | 2018-12-20 |
| HASH | 7090eb434f228705acd8d2da5e7c7899 | 2018-12-20 | 2018-12-20 |
| HASH | 282f3f17d7d6dc68e220fe328adc66c5 | 2018-12-20 | 2018-12-20 |
| HASH | fcceef71738e1506c4524e3210f4b23d | 2018-12-20 | 2018-12-20 |
| HASH | c9f0125b449dd44d112644901d787e3f | 2018-12-20 | 2018-12-20 |
| HASH | 38b3045a69ff6339adec25822d4d8e25 | 2018-12-20 | 2018-12-20 |
| [email protected] | 2018-12-20 | 2018-12-20 | |
| [email protected] | 2018-12-20 | 2018-12-20 | |
| URL | http://www.pudn.com/Download/it… | 2018-12-20 | 2018-12-20 |
| URL | http://filer2.1apps.com/1.txt | 2018-12-20 | 2018-12-20 |