Kimsuky 그룹의 xRAT(Quasar RAT) 유포 정황
2022-01-28 • Ahnlab • Circumstances of distribution of xRAT (Quasar RAT) by Kimsuky Group •
AhnLab observed Kimsuky using xRAT, an open-source Quasar RAT variant, alongside a Gold Dragon variant on an infected system in January 2022. The installer downloaded a GZip-compressed Gold Dragon payload from attacker infrastructure, unpacked it into the temp directory, and executed it with rundll32.exe before establishing persistence through an autorun registry key. The Gold Dragon variant reused known process-hollowing behavior against processes such as iexplore.exe and svchost.exe, but lacked earlier built-in system reconnaissance commands, suggesting that information theft had been modularized. The attacker then deployed cp1093.exe to run xRAT via process hollowing into a copied powershell_ise.exe process under C:\ProgramData\. Reported infrastructure and artifacts included sk5621.com.co, 45.77.71.50:8082, installer_sk5621.com.co.exe, glu32.dll, cp1093.exe, and an uninstall tool used to remove prior traces.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | com.co | 2022-01-28 | 2024-11-10 |
| HASH | 4ea6cee3ecd9bbd2faf3af73059736df | 2022-01-28 | 2022-01-28 |
| HASH | 40b428899db353bb0ea244d95b5b82d9 | 2022-01-28 | 2022-01-28 |
| HASH | 070f0390aad17883cc8fad2dc8bc81ba | 2022-01-28 | 2022-01-28 |
| HASH | b841d27fb7fee74142be38cee917eda5 | 2022-01-28 | 2022-01-28 |
| URL | https://sk5621.com.co | 2022-01-28 | 2022-01-28 |
| DOMAIN | sk5621.com.co | 2022-01-28 | 2022-01-28 |
| IPv4 | 45.77.71.50 | 2022-01-28 | 2022-01-28 |