Hermit(隐士)APT组织2020年最新攻击活动分析

2020-04-24 Tencent Analysis of the latest attack activities of the Hermit APT organization in 2020

https://s.tencent.com/research/report/969

Thumbnail for Hermit(隐士)APT组织2020年最新攻击活动分析

Tencent’s 2020 analysis describes Hermit, a Tencent-named cluster linked through correlation to KONNI/SYSCON/SANNY activity, continuing operations against Korean Peninsula-related NGOs, government bodies, trade companies, and media. The group used malicious Office macro lures tied to COVID-19, the 2020 Tokyo Paralympics, North Korea policy, and North Korean COVID-19 themes, hiding macro behavior by changing font colors and urging users to enable macros. The dropped downloader selected 32- or 64-bit payloads, decrypted CAB packages, used certutil-style download/decryption logic and multiple UAC bypass methods, and installed `wprint.dll` as a service. The RAT used FTP C2, collected system and process information, uploaded encrypted files, and pulled numbered command files for shell execution, file transfer, and payload execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 77f46253fd4ce7176df5db8f71585368 2020-04-24 2020-04-24
HASH ce26d4e20d936ebdad92f29f03dfc1d9 2020-04-24 2020-04-24
HASH 62e959528ae9280f39d49ba5c559d8fb 2020-04-24 2020-04-24
HASH a83ca91c55e7af71ac4f712610646fca 2020-04-24 2020-04-24
HASH 1a7232ef1386f78e76052827d8f703ae 2020-04-24 2020-04-24
HASH 7e71d5a0f1899212cea498bbda476ce8 2020-04-24 2020-04-24
HASH faf6492129eeca2633a68c9b8c2b8156 2020-04-24 2020-04-24
HASH 677e200c602b44dc0a6cc5f685f78413 2020-04-24 2020-04-24
HASH 40e7a1f37950277b115d5944b53eaf3c 2020-04-24 2020-04-24
DOMAIN myview-202001.c1.biz 2020-04-24 2020-04-24
DOMAIN win10-ms.c1.biz 2020-04-24 2020-04-24
DOMAIN firefox-plug.c1.biz 2020-04-24 2020-04-24
DOMAIN phpview.mygamesonline.org 2020-04-24 2020-04-24

Related Actors

Related Reports

« Back