Kimsuky APT组织利用假冒的ESET安全软件更新程序进行恶意活动
2020-05-28 • Threat Book • Kimsuky APT group uses fake ESET security software updates to conduct malicious activities •
AsiaInfo Security analyzed a suspected Kimsuky backdoor masquerading as an ESET software updater during COVID-19-themed targeting of South Korea. The malware created a GoogleUpdate_01 mutex, encrypted strings for functions, files, paths, and registry names, copied itself to a temporary directory, and added persistence before showing a fake update-success prompt. It generated network request fields from local network and system-version data, then handled C2 commands labeled with animal names such as tiger, lion, wolf, monkey, fox, and cat. The tiger command path executed system discovery commands such as dir and systeminfo, wrote results to tmp.LOG, and sent them back to the server, showing an information-collection focus consistent with earlier Kimsuky tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ae986dd436082fb9a7fec397c8b6e717 | 2020-05-28 | 2020-05-28 |