NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea
2018-05-31 • Cisco Talos •
Talos identified a malicious HWP document targeting Korean users with a decoy about the prospective U.S.-North Korea summit and assessed with medium confidence that the NavRAT campaign was linked to Group123. The infection chain used an embedded EPS object to execute shellcode, download an image-hosted payload from a compromised Korean website, and run the decoded executable in memory. NavRAT supported file upload, download, command execution, keylogging, process injection into Internet Explorer, and persistence by copying itself as GoogleUpdate.exe under a fake AhnLab-related path. Its C2 design abused the Naver email platform for operator communication, with attempted data delivery to a Daum address, making the campaign notable for using a South Korea-popular email service as command infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e0257d187be69b9bee0a731437bf050… | 2018-05-31 | 2020-03-09 |
| HASH | 4f06eaed3dd67ce31e7c8258741cf72… | 2018-05-31 | 2020-03-09 |
| DOMAIN | mailacounts.com | 2018-05-31 | 2019-09-02 |
| DOMAIN | artndesign2.cafe24.com | 2018-05-31 | 2019-08-24 |
| HASH | e5f191531bc1c674ea74f8885449f4d… | 2018-05-31 | 2018-05-31 |
| [email protected] | 2018-05-31 | 2018-05-31 | |
| URL | http://artndesign2.cafe24.com:8… | 2018-05-31 | 2018-05-31 |