Hermit(隐士)APT组织2020年最新攻击活动分析
2020-04-24 • Tencent • Analysis of the latest attack activities of the Hermit APT organization in 2020 •
Tencent’s 2020 analysis describes Hermit, a Tencent-named cluster linked through correlation to KONNI/SYSCON/SANNY activity, continuing operations against Korean Peninsula-related NGOs, government bodies, trade companies, and media. The group used malicious Office macro lures tied to COVID-19, the 2020 Tokyo Paralympics, North Korea policy, and North Korean COVID-19 themes, hiding macro behavior by changing font colors and urging users to enable macros. The dropped downloader selected 32- or 64-bit payloads, decrypted CAB packages, used certutil-style download/decryption logic and multiple UAC bypass methods, and installed `wprint.dll` as a service. The RAT used FTP C2, collected system and process information, uploaded encrypted files, and pulled numbered command files for shell execution, file transfer, and payload execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 77f46253fd4ce7176df5db8f71585368 | 2020-04-24 | 2020-04-24 |
| HASH | ce26d4e20d936ebdad92f29f03dfc1d9 | 2020-04-24 | 2020-04-24 |
| HASH | 62e959528ae9280f39d49ba5c559d8fb | 2020-04-24 | 2020-04-24 |
| HASH | a83ca91c55e7af71ac4f712610646fca | 2020-04-24 | 2020-04-24 |
| HASH | 1a7232ef1386f78e76052827d8f703ae | 2020-04-24 | 2020-04-24 |
| HASH | 7e71d5a0f1899212cea498bbda476ce8 | 2020-04-24 | 2020-04-24 |
| HASH | faf6492129eeca2633a68c9b8c2b8156 | 2020-04-24 | 2020-04-24 |
| HASH | 677e200c602b44dc0a6cc5f685f78413 | 2020-04-24 | 2020-04-24 |
| HASH | 40e7a1f37950277b115d5944b53eaf3c | 2020-04-24 | 2020-04-24 |
| DOMAIN | myview-202001.c1.biz | 2020-04-24 | 2020-04-24 |
| DOMAIN | win10-ms.c1.biz | 2020-04-24 | 2020-04-24 |
| DOMAIN | firefox-plug.c1.biz | 2020-04-24 | 2020-04-24 |
| DOMAIN | phpview.mygamesonline.org | 2020-04-24 | 2020-04-24 |