Kimsuky(APT-Q-2)组织近期 Endoor 恶意软件分析

2025-06-18 Qianxin Analysis of Recent Endoor Malware from the Kimsuky (APT-Q-2) Group

https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247515137&idx=1&sn=98a66e3565c09db9b5a0d0fc4674177b

Thumbnail for Kimsuky(APT-Q-2)组织近期 Endoor 恶意软件分析

QiAnXin attributes recent Endoor samples to Kimsuky, tracked internally as APT-Q-2, and notes the group’s historical focus on South Korean defense, education, energy, government, healthcare, and think-tank targets. The Go-based backdoor appears in both DLL form and an EXE loader that decrypts and memory-loads the same core Endoor code, then builds a victim UID from hostname, username, and admin status before enforcing single-instance execution with a UID-named lock file. Endoor communicates by POST with hxxp://june.drydate.p-e.kr:53/, encrypts and base64-encodes command traffic, and supports remote shell execution, directory and system discovery, upload/download, TCP connections, SOCKS5 proxying, hibernation, shell/codepage configuration, and self-deletion. The report highlights persistence via a scheduled task named "Windows Backup" in the EXE mode, a hardcoded self-delete path bug, GitHub-like path strings used as camouflage, and related infrastructure including 162.216.114.133, summer.cooldate.p-e.kr, and uni.oxford.p-e.kr.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d4db59139f2ae0b5c5da192d8c6c5fa0 2025-06-18 2025-06-18
HASH e5c4f8ad27df5aa60ceb36972e29a5fb 2025-06-18 2025-06-18
HASH b15cadf2a4e6670c075f80d618b26093 2025-06-18 2025-06-18
URL http://june.drydate.p-e.kr:53/ 2025-06-18 2025-06-18
DOMAIN local.github.com 2025-06-18 2025-06-18
DOMAIN june.drydate.p-e.kr 2025-06-18 2025-06-18
DOMAIN uni.oxford.p-e.kr 2025-06-18 2025-06-18
DOMAIN summer.cooldate.p-e.kr 2025-06-18 2025-06-18
IPv4 162.216.114.133 2025-06-18 2025-06-18

Related Actors

Related Reports

« Back