NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea

2018-05-31 Cisco Talos

https://blog.talosintelligence.com/2018/05/navrat.html

Thumbnail for NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea

Talos identified a malicious HWP document targeting Korean users with a decoy about the prospective U.S.-North Korea summit and assessed with medium confidence that the NavRAT campaign was linked to Group123. The infection chain used an embedded EPS object to execute shellcode, download an image-hosted payload from a compromised Korean website, and run the decoded executable in memory. NavRAT supported file upload, download, command execution, keylogging, process injection into Internet Explorer, and persistence by copying itself as GoogleUpdate.exe under a fake AhnLab-related path. Its C2 design abused the Naver email platform for operator communication, with attempted data delivery to a Daum address, making the campaign notable for using a South Korea-popular email service as command infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e0257d187be69b9bee0a731437bf050… 2018-05-31 2020-03-09
HASH 4f06eaed3dd67ce31e7c8258741cf72… 2018-05-31 2020-03-09
DOMAIN mailacounts.com 2018-05-31 2019-09-02
DOMAIN artndesign2.cafe24.com 2018-05-31 2019-08-24
HASH e5f191531bc1c674ea74f8885449f4d… 2018-05-31 2018-05-31
EMAIL [email protected] 2018-05-31 2018-05-31
URL http://artndesign2.cafe24.com:8… 2018-05-31 2018-05-31

Related Reports

« Back