Kimsuky 그룹의 신규 백도어 등장 (HappyDoor)
2024-06-26 • Ahnlab • New Kimsuky Backdoor Appears (HappyDoor) •
AhnLab analyzed HappyDoor, a Kimsuky backdoor first collected in 2021 and still observed in 2024 with patched versions, hard-coded version data, and recent samples labeled “happy” 4.2. The malware is distributed through spear-phishing attachments containing obfuscated JScript or executable droppers that launch a decoy document and install the DLL through regsvr32.exe with staged arguments such as install*, init*, and run*. HappyDoor establishes persistence with a scheduled task, stores configuration under Microsoft Notepad and FTP registry paths, and uses HTTP C2 to validate packets, exfiltrate data, and receive backdoor commands. Its collection functions include screenshots, keylogging, file theft from user directories, portable-device and Android MTP file collection, microphone recording, system information gathering, and command execution results, with stolen data encrypted using RSA and RC4 before exfiltration. The report provides hashes, install arguments, paths, C2 URLs, and behavioral artifacts that help defenders distinguish HappyDoor from AppleSeed and hunt for Kimsuky intrusions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d9b15979e76dd5d18c31e62ab9ff7dae | 2024-06-26 | 2024-07-05 |
| HASH | 0054bdfe4cac0cb7a717749f8c08f5f3 | 2024-06-26 | 2024-07-05 |
| HASH | 4ef5e3ce535f84f975a8212f5630bfe8 | 2024-06-26 | 2024-07-05 |
| HASH | a1c59fec34fec1156e7db27ec16121a7 | 2024-06-26 | 2024-07-05 |
| HASH | c7b82b4bafb677bf0f4397b0b88ccfa2 | 2024-06-26 | 2024-07-05 |
| URL | http://aa.olixa.p-e.kr/index.php | 2024-06-26 | 2024-07-05 |
| URL | http://app.seoul.minia.ml/kinsa… | 2024-06-26 | 2024-07-05 |
| URL | http://users.nya.pub/index.php | 2024-06-26 | 2024-07-05 |
| URL | http://ai.hyyeo.p-e.kr/index.php | 2024-06-26 | 2024-07-05 |
| URL | http://uo.zosua.o-r.kr/index.php | 2024-06-26 | 2024-07-05 |
| URL | http://go.ktspace.p-e.kr/index.… | 2024-06-26 | 2024-07-05 |
| URL | http://on.ktspace.p-e.kr/index.… | 2024-06-26 | 2024-07-05 |
| URL | http://jp.hyyeo.p-e.kr/index.php | 2024-06-26 | 2024-07-05 |
| DOMAIN | ai.hyyeo.p-e.kr | 2024-06-26 | 2024-07-05 |
| DOMAIN | go.ktspace.p-e.kr | 2024-06-26 | 2024-07-05 |
| DOMAIN | jp.hyyeo.p-e.kr | 2024-06-26 | 2024-07-05 |
| DOMAIN | on.ktspace.p-e.kr | 2024-06-26 | 2024-07-05 |
| DOMAIN | users.nya.pub | 2024-06-26 | 2024-07-05 |
| DOMAIN | app.seoul.minia.ml | 2024-06-26 | 2024-07-05 |
| DOMAIN | uo.zosua.o-r.kr | 2024-03-25 | 2024-07-05 |