NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

2018-10-01 Paloalto Networks

https://researchcenter.paloaltonetworks.com/2018/10/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/

Thumbnail for NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

Unit 42 linked NOKKI-related delivery activity to Reaper Group tradecraft by identifying a World Cup lure document that ultimately executed DOGCALL, a RAT publicly associated with North Korea-linked Reaper activity. The malicious Word macro used a distinctive base64-to-hex deobfuscation routine, downloaded a remote VBScript wrapped in HTML, and then staged additional payloads from kmbr1.nitesbr1[.]org. The second stage wrote configuration data under the user’s Microsoft application data path, downloaded files masquerading as images, and launched an executable and DLL pair that Unit 42 named Final1stspy. Final1stspy decrypted and loaded a DLL, established persistence through a Run key pointing to ieConv.exe, collected basic system information, and communicated with a hardcoded URL using the user-agent “Host Process Update.” The evidence matters because it connects lure-based document delivery, a new dropper family, and DOGCALL deployment in activity aligned with Reaper’s North Korea-linked targeting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fb94a5e30de7afd1d9072ccedd90a24… 2018-10-01 2020-03-09
URL http://kmbr1.nitesbr1.org/UserF… 2018-10-01 2019-05-14
DOMAIN kmbr1.nitesbr1.org 2018-10-01 2019-05-14
HASH 0669c71740134323793429d10518576… 2018-10-01 2018-10-03
HASH 0f1d3ed85fee2acc23a8a26e0dc12e0f 2018-10-01 2018-10-01
HASH 66a0c294ee8f3507d723a3760657986… 2018-10-01 2018-10-01
HASH a2fe5dcb08ae8b72e8bc98ddc0b918e7 2018-10-01 2018-10-01
HASH 05d43d417a8f50e7b23246643fc7e03d 2018-10-01 2018-10-01
HASH d13fc918433c705b49db74c91f56ae6… 2018-10-01 2018-10-01
HASH 741dbdb20d1beeb8ff809291996c8b7… 2018-10-01 2018-10-01
HASH 67c05b3937d94136eda4a60a2d5fb68… 2018-10-01 2018-10-01
HASH 3fee068bf90ffbeb25549eb52be0456… 2018-10-01 2018-10-01
HASH e02024f38dfb6290ce0d693539a285a9 2018-10-01 2018-10-01
HASH 3d161de48d3f4da0aefff685253404c… 2018-10-01 2018-10-01
URL http://kmbr1.nitesbr1.org/UserF… 2018-10-01 2018-10-01
URL http://kmbr1.nitesbr1.org/UserF… 2018-10-01 2018-10-01
URL http://kmbr1.nitesbr1.org/UserF… 2018-10-01 2018-10-01

Related Actors

Related Reports

« Back