Kimsuky(APT-Q-2)组织近期 Endoor 恶意软件分析
2025-06-18 • Qianxin • Analysis of Recent Endoor Malware from the Kimsuky (APT-Q-2) Group •
QiAnXin attributes recent Endoor samples to Kimsuky, tracked internally as APT-Q-2, and notes the group’s historical focus on South Korean defense, education, energy, government, healthcare, and think-tank targets. The Go-based backdoor appears in both DLL form and an EXE loader that decrypts and memory-loads the same core Endoor code, then builds a victim UID from hostname, username, and admin status before enforcing single-instance execution with a UID-named lock file. Endoor communicates by POST with hxxp://june.drydate.p-e.kr:53/, encrypts and base64-encodes command traffic, and supports remote shell execution, directory and system discovery, upload/download, TCP connections, SOCKS5 proxying, hibernation, shell/codepage configuration, and self-deletion. The report highlights persistence via a scheduled task named "Windows Backup" in the EXE mode, a hardcoded self-delete path bug, GitHub-like path strings used as camouflage, and related infrastructure including 162.216.114.133, summer.cooldate.p-e.kr, and uni.oxford.p-e.kr.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d4db59139f2ae0b5c5da192d8c6c5fa0 | 2025-06-18 | 2025-06-18 |
| HASH | e5c4f8ad27df5aa60ceb36972e29a5fb | 2025-06-18 | 2025-06-18 |
| HASH | b15cadf2a4e6670c075f80d618b26093 | 2025-06-18 | 2025-06-18 |
| URL | http://june.drydate.p-e.kr:53/ | 2025-06-18 | 2025-06-18 |
| DOMAIN | local.github.com | 2025-06-18 | 2025-06-18 |
| DOMAIN | june.drydate.p-e.kr | 2025-06-18 | 2025-06-18 |
| DOMAIN | uni.oxford.p-e.kr | 2025-06-18 | 2025-06-18 |
| DOMAIN | summer.cooldate.p-e.kr | 2025-06-18 | 2025-06-18 |
| IPv4 | 162.216.114.133 | 2025-06-18 | 2025-06-18 |