North Korean APT InkySquid Infects Victims Using Browser Exploits

2021-08-17 Volexity

https://www.volexity.com/blog/2021/08/17/north-korean-apt-inkysquid-infects-victims-using-browser-exploits/

Thumbnail for North Korean APT InkySquid Infects Victims Using Browser Exploits

Volexity attributes a strategic web compromise of Daily NK to InkySquid, an activity set broadly corresponding to ScarCruft/APT37. From late March through early June 2021, attackers modified legitimate Daily NK JavaScript to redirect selected visitors to jquery[.]services infrastructure that served Internet Explorer and legacy Edge exploits, including CVE-2020-1380 and CVE-2021-26411. Successful exploitation delivered Cobalt Strike stagers and, in a later case, an XOR-encoded custom malware family named BLUELIGHT from storage.jquery[.]services. The report is significant because it shows a North Korean actor using short-lived website injections, browser exploits, obfuscated JavaScript, and custom payloads against readers of a South Korea-focused news site.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9b86888a83dd0dd1c3a0929f1ea53b82 2021-08-17 2021-08-17
HASH 5c430e2770b59cceba1f1587b34e686… 2021-08-17 2021-08-17
HASH 558ce5e8c0b1b0a76b88db087f0c92f… 2021-08-17 2021-08-17

Related Actors

Related Reports

« Back