North Korea's Hackers Caught Red-Handed: The Cyberstanc Revelation
2023-09-15 • Cyberstanc •
https://cyberstanc.com/blog/north-koreas-hackers-caught-red-handed-by-cyberstanc/
Cyberstanc links the SuperBear sample to suspected North Korean Kimsuky activity targeting APAC civil society groups and activists through a phishing email from a trusted organizational source. The infection chain begins with a malicious LNK file, followed by PowerShell and Visual Basic stages that retrieve payloads from a compromised WordPress site. Analysis found SuperBear closely mirrors Cyberstanc's open-source Chimera Loader code, including near-identical C2 logic, but swaps in actor-controlled infrastructure such as hironchk[.]com. The sample functions more like a dropper than a full RAT, supporting commands for message display, process and system reconnaissance, shell command execution, and DLL download, with collected data written to proc.db and sys.db before upload. The case matters because it shows Kimsuky-associated operators adapting public loader code for targeted phishing operations while leaving recognizable implementation artifacts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 89.117.139.230 | 2023-09-01 | 2023-09-15 |
| HASH | 282e926eb90960a8a807dd0b9e8668e… | 2023-08-31 | 2023-09-15 |
| DOMAIN | hironchk.com | 2023-08-31 | 2023-09-15 |