Kimsuky APT组织利用假冒的ESET安全软件更新程序进行恶意活动

2020-05-28 Threat Book Kimsuky APT group uses fake ESET security software updates to conduct malicious activities

https://www.freebuf.com/articles/terminal/235603.html

AsiaInfo Security analyzed a suspected Kimsuky backdoor masquerading as an ESET software updater during COVID-19-themed targeting of South Korea. The malware created a GoogleUpdate_01 mutex, encrypted strings for functions, files, paths, and registry names, copied itself to a temporary directory, and added persistence before showing a fake update-success prompt. It generated network request fields from local network and system-version data, then handled C2 commands labeled with animal names such as tiger, lion, wolf, monkey, fox, and cat. The tiger command path executed system discovery commands such as dir and systeminfo, wrote results to tmp.LOG, and sent them back to the server, showing an information-collection focus consistent with earlier Kimsuky tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ae986dd436082fb9a7fec397c8b6e717 2020-05-28 2020-05-28

Related Actors

Related Reports

« Back