Kimsuky APT组织对韩国国防安全相关部门的定向攻击活动分析
2021-06-23 • Qihoo360 • Analysis of Kimsuky APT's targeted attack activities on South Korean defense and security-related departments •
ThreatBook described Kimsuky activity targeting South Korean defense and security-related organizations over roughly six months with lures themed around the U.S.-South Korea summit, Ministry of National Defense bidding documents, and a fake KISA mobile security app. The Windows infection chains disguised malware as HWP documents or Microsoft-style components, used mshta.exe to retrieve remote scripts from infrastructure such as mail.kumb.cf and v*p*n.atooi.ga, and deployed espionage RAT components with persistence, remote shell, file transfer, keylogging, screen capture, file monitoring, and USB monitoring functions. The Android variant masqueraded as “KISA Mobile Security,” requested sensitive permissions, contacted app.at-me.ml, and collected SMS and file information. The report also linked several domains to 104.128.239.70 and noted Korean reporting that Kimsuky abused VPN access in the KAERI intrusion, while treating any Lazarus coordination as a suspected overlap rather than a confirmed attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 16b3487022b674040227afc8979ffed… | 2021-06-23 | 2021-09-12 |
| HASH | e7caf25de7ce463a6f22ecb8689389ad | 2021-06-23 | 2021-09-12 |
| HASH | fe1a734019f0dc714bd3360e2369853… | 2021-06-03 | 2021-09-12 |
| DOMAIN | app.at-me.ml | 2021-06-03 | 2021-09-12 |
| IPv4 | 104.128.239.70 | 2021-06-03 | 2021-09-12 |
| HASH | 1302ef3a4b3ebd2127b21ec56e140cf… | 2021-06-23 | 2021-06-23 |
| HASH | c861f25bb943f77a909b33d62bb71926 | 2021-06-23 | 2021-06-23 |
| HASH | 742e04ae5f2cd42cf514abbd1956c59… | 2021-06-23 | 2021-06-23 |
| HASH | 97e2f035a2fac5ee8d07a204fcf36ed… | 2021-06-23 | 2021-06-23 |
| HASH | f0255dfcb932c3072c2489124b25b373 | 2021-06-23 | 2021-06-23 |
| HASH | 2dccc8eb48bc7bdbde42cc4450086ac… | 2021-06-23 | 2021-06-23 |
| HASH | 679a17688cde5d57c4662df12ab134f… | 2021-06-23 | 2021-06-23 |
| HASH | 576b953cb4fe71adb71a338a42524b0… | 2021-06-23 | 2021-06-23 |
| HASH | fd59597169668b90c47d0ad6db1bcd7… | 2021-06-23 | 2021-06-23 |
| HASH | 6184acd90c735783aafd32c3346c943… | 2021-06-23 | 2021-06-23 |
| URL | http://app.at-me.ml/index.php?m… | 2021-06-23 | 2021-06-23 |
| URL | http://mail.kumb.cf/?query=5 | 2021-06-23 | 2021-06-23 |
| DOMAIN | mail.kumb.cf | 2021-06-23 | 2021-06-23 |
| URL | http://app.at-me.ml/index.php | 2021-06-03 | 2021-06-23 |
| HASH | 7e041b101e1e574fb81f3f0cdf1c72b8 | 2021-02-03 | 2021-06-23 |