Kimsuky 그룹의 xRAT(Quasar RAT) 유포 정황

2022-01-28 Ahnlab Circumstances of distribution of xRAT (Quasar RAT) by Kimsuky Group

https://asec.ahnlab.com/ko/30953/

Thumbnail for Kimsuky 그룹의 xRAT(Quasar RAT) 유포 정황

AhnLab observed Kimsuky using xRAT, an open-source Quasar RAT variant, alongside a Gold Dragon variant on an infected system in January 2022. The installer downloaded a GZip-compressed Gold Dragon payload from attacker infrastructure, unpacked it into the temp directory, and executed it with rundll32.exe before establishing persistence through an autorun registry key. The Gold Dragon variant reused known process-hollowing behavior against processes such as iexplore.exe and svchost.exe, but lacked earlier built-in system reconnaissance commands, suggesting that information theft had been modularized. The attacker then deployed cp1093.exe to run xRAT via process hollowing into a copied powershell_ise.exe process under C:\ProgramData\. Reported infrastructure and artifacts included sk5621.com.co, 45.77.71.50:8082, installer_sk5621.com.co.exe, glu32.dll, cp1093.exe, and an uninstall tool used to remove prior traces.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN com.co 2022-01-28 2024-11-10
HASH 4ea6cee3ecd9bbd2faf3af73059736df 2022-01-28 2022-01-28
HASH 40b428899db353bb0ea244d95b5b82d9 2022-01-28 2022-01-28
HASH 070f0390aad17883cc8fad2dc8bc81ba 2022-01-28 2022-01-28
HASH b841d27fb7fee74142be38cee917eda5 2022-01-28 2022-01-28
URL https://sk5621.com.co 2022-01-28 2022-01-28
DOMAIN sk5621.com.co 2022-01-28 2022-01-28
IPv4 45.77.71.50 2022-01-28 2022-01-28

Related Actors

Related Reports

« Back