Kimsuky 그룹, ADS를 활용하여 악성코드 은폐
2023-03-24 • Ahnlab • Kimsuky group uses ADS to conceal malware •
ASEC observed Kimsuky hiding malware with Windows Alternate Data Streams (ADS). The infection begins with VBScript embedded in an HTML file and functions as an infostealer that collects directory and recent-file information before decoding a payload to C:\ProgramData\Uso2. Persistence is established through a scheduled task that repeatedly runs a script which contacts C2 and executes additional scripts, while the file is stored as .Uso2Config.conf:honeyT so normal directory listings show a zero-byte host file. ASEC identifies the activity as Downloader/VBS.Kimsuky.S1997 and cites representative indicators including zetaros.000webhostapp[.]com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | aca61a168d95c5f72b8e02650f727000 | 2023-03-24 | 2023-05-24 |
| HASH | ec3c0d9cbf4e27e0240c5b5d888687ec | 2023-03-24 | 2023-03-29 |
| DOMAIN | zetaros.000webhostapp.com | 2023-03-24 | 2023-03-29 |