Meterpreter를 이용해 웹 서버를 공격하는 Kimsuky 그룹

2023-05-15 Ahnlab Kimsuky group attacks web servers using Meterpreter

https://asec.ahnlab.com/ko/52662/

Thumbnail for Meterpreter를 이용해 웹 서버를 공격하는 Kimsuky 그룹

ASEC reports that Kimsuky attacked a South Korean architectural firm’s Windows IIS web server, likely exploiting an unpatched or poorly managed server to run PowerShell through w3wp.exe. The attacker downloaded a Metasploit Meterpreter backdoor from 45.58.52[.]82 and then used Meterpreter to install an additional Go-based proxy malware. The malware was loaded as a DLL through regsvr32.exe, matching earlier Kimsuky tradecraft, while the newer Go stager and proxy suggest an attempt to evade detection. The proxy accepted IP and port arguments, used an “aPpLe” validation string, and appeared intended to enable later RDP access to the compromised system.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.58.52.82 2023-05-15 2023-11-01
HASH 6b2062e61bcb46ce5ff19b329ce31b03 2023-05-15 2023-05-21
HASH 000130a373ea4085b87b97a0c7000c86 2023-05-15 2023-05-21

Related Actors

Related Reports

« Back