Kimsuky APT组织使用新型的AppleSeed Android组件伪装成安全软件对韩特定目标进行攻击
2021-05-06 • Qihoo360 • The Kimsuky APT organization uses the new AppleSeed Android component to disguise itself as security software to attack specific targets in South Korea. •
The source describes Kimsuky activity using a new Android component associated with AppleSeed/AutoUpdate and disguised as a KISA mobile security-check application to target selected South Korean victims. The APK collected Android device information, contacted download.riseknite.life with m=a, m=c, and m=d parameters, enumerated files under /sdcard, uploaded disguised and encrypted archives, executed commands, read SMS messages, and could send SMS or clear app data. The report also correlates the Android backdoor with Kimsuky Windows droppers and AppleSeed DLL infrastructure, including onedrive-upload.ikpoo.cf, based on similar traffic parameters and decryption logic. The activity illustrates Kimsuky’s continued expansion across Windows and Android payloads against South Korea-focused targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a03598cd616f86998daef034d6be2ec5 | 2021-05-06 | 2021-05-06 |
| HASH | 4626ed60dfc8deaf75477bc06bd39be7 | 2021-05-06 | 2021-05-06 |
| URL | http://download.riseknite.life/… | 2021-05-06 | 2021-05-06 |
| DOMAIN | download.riseknite.life | 2021-05-06 | 2021-05-06 |
| HASH | 14b95dc99e797c6c717bf68440eae720 | 2021-05-06 | 2021-05-06 |
| HASH | 3a4ab11b25961becece1c358029ba611 | 2021-05-06 | 2021-05-06 |
| HASH | 80a2bb7884b8bad4a8e83c2cb03ee343 | 2021-05-06 | 2021-05-06 |