Kimsuky APT组织对韩国国防安全相关部门的定向攻击活动分析

2021-06-23 Qihoo360 Analysis of Kimsuky APT's targeted attack activities on South Korean defense and security-related departments

https://www.freebuf.com/articles/paper/278762.html

Thumbnail for Kimsuky APT组织对韩国国防安全相关部门的定向攻击活动分析

ThreatBook described Kimsuky activity targeting South Korean defense and security-related organizations over roughly six months with lures themed around the U.S.-South Korea summit, Ministry of National Defense bidding documents, and a fake KISA mobile security app. The Windows infection chains disguised malware as HWP documents or Microsoft-style components, used mshta.exe to retrieve remote scripts from infrastructure such as mail.kumb.cf and v*p*n.atooi.ga, and deployed espionage RAT components with persistence, remote shell, file transfer, keylogging, screen capture, file monitoring, and USB monitoring functions. The Android variant masqueraded as “KISA Mobile Security,” requested sensitive permissions, contacted app.at-me.ml, and collected SMS and file information. The report also linked several domains to 104.128.239.70 and noted Korean reporting that Kimsuky abused VPN access in the KAERI intrusion, while treating any Lazarus coordination as a suspected overlap rather than a confirmed attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 16b3487022b674040227afc8979ffed… 2021-06-23 2021-09-12
HASH e7caf25de7ce463a6f22ecb8689389ad 2021-06-23 2021-09-12
HASH fe1a734019f0dc714bd3360e2369853… 2021-06-03 2021-09-12
DOMAIN app.at-me.ml 2021-06-03 2021-09-12
IPv4 104.128.239.70 2021-06-03 2021-09-12
HASH 1302ef3a4b3ebd2127b21ec56e140cf… 2021-06-23 2021-06-23
HASH c861f25bb943f77a909b33d62bb71926 2021-06-23 2021-06-23
HASH 742e04ae5f2cd42cf514abbd1956c59… 2021-06-23 2021-06-23
HASH 97e2f035a2fac5ee8d07a204fcf36ed… 2021-06-23 2021-06-23
HASH f0255dfcb932c3072c2489124b25b373 2021-06-23 2021-06-23
HASH 2dccc8eb48bc7bdbde42cc4450086ac… 2021-06-23 2021-06-23
HASH 679a17688cde5d57c4662df12ab134f… 2021-06-23 2021-06-23
HASH 576b953cb4fe71adb71a338a42524b0… 2021-06-23 2021-06-23
HASH fd59597169668b90c47d0ad6db1bcd7… 2021-06-23 2021-06-23
HASH 6184acd90c735783aafd32c3346c943… 2021-06-23 2021-06-23
URL http://app.at-me.ml/index.php?m… 2021-06-23 2021-06-23
URL http://mail.kumb.cf/?query=5 2021-06-23 2021-06-23
DOMAIN mail.kumb.cf 2021-06-23 2021-06-23
URL http://app.at-me.ml/index.php 2021-06-03 2021-06-23
HASH 7e041b101e1e574fb81f3f0cdf1c72b8 2021-02-03 2021-06-23

Related Actors

Related Reports

« Back