Novel RAT discovered “SuperBear” targeting journalist covering geopolitics of Asia
2023-09-01 • Inter Lab •
Interlab analyzed a targeted email attack against a journalist covering Asian geopolitics that delivered a malicious LNK file and a decoy DOCX, with loose attribution to Kimsuky based on initial-vector and code similarities. Execution launched an obfuscated PowerShell chain that extracted and ran embedded content, created a VBS script, and used curl to download AutoIT3 and a packed AutoIT script from a compromised WordPress site. The AutoIT script performed process hollowing into Explorer.exe and injected a newly named SuperBear RAT. SuperBear connected to hironchk.com at 89.117.139.230 and supported process and system-data exfiltration, shell-command execution, and DLL download and execution. The activity matters because it shows a civil-society targeting chain using open-source AutoIT tooling and a novel RAT while the report cautions that infrastructure overlap with Kimsuky has not been observed.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 89.117.139.230 | 2023-09-01 | 2023-09-15 |
| HASH | 282e926eb90960a8a807dd0b9e8668e… | 2023-08-31 | 2023-09-15 |
| DOMAIN | hironchk.com | 2023-08-31 | 2023-09-15 |
| HASH | 5305b8969b33549b6bd4b68a3f9a2db… | 2023-08-31 | 2023-09-14 |
| HASH | 454cfe3be695d0a387d7877c11d3b22… | 2023-08-31 | 2023-09-14 |
| URL | https://syra.forumcommunity.net… | 2023-08-31 | 2023-09-14 |
| DOMAIN | autoit-script.ru | 2023-08-31 | 2023-09-14 |
| DOMAIN | syra.forumcommunity.net | 2023-08-31 | 2023-09-14 |
| HASH | 614dda72d95b5dfd732916aec0662598 | 2023-09-01 | 2023-09-01 |