Kimsuky 그룹의 신규 백도어 등장 (HappyDoor)

2024-06-26 Ahnlab New Kimsuky Backdoor Appears (HappyDoor)

https://asec.ahnlab.com/ko/67128/

Thumbnail for Kimsuky 그룹의 신규 백도어 등장 (HappyDoor)

AhnLab analyzed HappyDoor, a Kimsuky backdoor first collected in 2021 and still observed in 2024 with patched versions, hard-coded version data, and recent samples labeled “happy” 4.2. The malware is distributed through spear-phishing attachments containing obfuscated JScript or executable droppers that launch a decoy document and install the DLL through regsvr32.exe with staged arguments such as install*, init*, and run*. HappyDoor establishes persistence with a scheduled task, stores configuration under Microsoft Notepad and FTP registry paths, and uses HTTP C2 to validate packets, exfiltrate data, and receive backdoor commands. Its collection functions include screenshots, keylogging, file theft from user directories, portable-device and Android MTP file collection, microphone recording, system information gathering, and command execution results, with stolen data encrypted using RSA and RC4 before exfiltration. The report provides hashes, install arguments, paths, C2 URLs, and behavioral artifacts that help defenders distinguish HappyDoor from AppleSeed and hunt for Kimsuky intrusions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d9b15979e76dd5d18c31e62ab9ff7dae 2024-06-26 2024-07-05
HASH 0054bdfe4cac0cb7a717749f8c08f5f3 2024-06-26 2024-07-05
HASH 4ef5e3ce535f84f975a8212f5630bfe8 2024-06-26 2024-07-05
HASH a1c59fec34fec1156e7db27ec16121a7 2024-06-26 2024-07-05
HASH c7b82b4bafb677bf0f4397b0b88ccfa2 2024-06-26 2024-07-05
URL http://aa.olixa.p-e.kr/index.php 2024-06-26 2024-07-05
URL http://app.seoul.minia.ml/kinsa… 2024-06-26 2024-07-05
URL http://users.nya.pub/index.php 2024-06-26 2024-07-05
URL http://ai.hyyeo.p-e.kr/index.php 2024-06-26 2024-07-05
URL http://uo.zosua.o-r.kr/index.php 2024-06-26 2024-07-05
URL http://go.ktspace.p-e.kr/index.… 2024-06-26 2024-07-05
URL http://on.ktspace.p-e.kr/index.… 2024-06-26 2024-07-05
URL http://jp.hyyeo.p-e.kr/index.php 2024-06-26 2024-07-05
DOMAIN ai.hyyeo.p-e.kr 2024-06-26 2024-07-05
DOMAIN go.ktspace.p-e.kr 2024-06-26 2024-07-05
DOMAIN jp.hyyeo.p-e.kr 2024-06-26 2024-07-05
DOMAIN on.ktspace.p-e.kr 2024-06-26 2024-07-05
DOMAIN users.nya.pub 2024-06-26 2024-07-05
DOMAIN app.seoul.minia.ml 2024-06-26 2024-07-05
DOMAIN uo.zosua.o-r.kr 2024-03-25 2024-07-05

Related Actors

Related Reports

« Back