Kimsuky 그룹, ADS를 활용하여 악성코드 은폐

2023-03-24 Ahnlab Kimsuky group uses ADS to conceal malware

https://asec.ahnlab.com/ko/50394/

Thumbnail for Kimsuky 그룹, ADS를 활용하여 악성코드 은폐

ASEC observed Kimsuky hiding malware with Windows Alternate Data Streams (ADS). The infection begins with VBScript embedded in an HTML file and functions as an infostealer that collects directory and recent-file information before decoding a payload to C:\ProgramData\Uso2. Persistence is established through a scheduled task that repeatedly runs a script which contacts C2 and executes additional scripts, while the file is stored as .Uso2Config.conf:honeyT so normal directory listings show a zero-byte host file. ASEC identifies the activity as Downloader/VBS.Kimsuky.S1997 and cites representative indicators including zetaros.000webhostapp[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aca61a168d95c5f72b8e02650f727000 2023-03-24 2023-05-24
HASH ec3c0d9cbf4e27e0240c5b5d888687ec 2023-03-24 2023-03-29
DOMAIN zetaros.000webhostapp.com 2023-03-24 2023-03-29

Related Actors

Related Reports

« Back