North Korean APT InkySquid Infects Victims Using Browser Exploits
2021-08-17 • Volexity •
Volexity attributes a strategic web compromise of Daily NK to InkySquid, an activity set broadly corresponding to ScarCruft/APT37. From late March through early June 2021, attackers modified legitimate Daily NK JavaScript to redirect selected visitors to jquery[.]services infrastructure that served Internet Explorer and legacy Edge exploits, including CVE-2020-1380 and CVE-2021-26411. Successful exploitation delivered Cobalt Strike stagers and, in a later case, an XOR-encoded custom malware family named BLUELIGHT from storage.jquery[.]services. The report is significant because it shows a North Korean actor using short-lived website injections, browser exploits, obfuscated JavaScript, and custom payloads against readers of a South Korea-focused news site.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9b86888a83dd0dd1c3a0929f1ea53b82 | 2021-08-17 | 2021-08-17 |
| HASH | 5c430e2770b59cceba1f1587b34e686… | 2021-08-17 | 2021-08-17 |
| HASH | 558ce5e8c0b1b0a76b88db087f0c92f… | 2021-08-17 | 2021-08-17 |