Novel RAT discovered “SuperBear” targeting journalist covering geopolitics of Asia

2023-09-01 Inter Lab

https://interlab.or.kr/archives/19416

Interlab analyzed a targeted email attack against a journalist covering Asian geopolitics that delivered a malicious LNK file and a decoy DOCX, with loose attribution to Kimsuky based on initial-vector and code similarities. Execution launched an obfuscated PowerShell chain that extracted and ran embedded content, created a VBS script, and used curl to download AutoIT3 and a packed AutoIT script from a compromised WordPress site. The AutoIT script performed process hollowing into Explorer.exe and injected a newly named SuperBear RAT. SuperBear connected to hironchk.com at 89.117.139.230 and supported process and system-data exfiltration, shell-command execution, and DLL download and execution. The activity matters because it shows a civil-society targeting chain using open-source AutoIT tooling and a novel RAT while the report cautions that infrastructure overlap with Kimsuky has not been observed.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 89.117.139.230 2023-09-01 2023-09-15
HASH 282e926eb90960a8a807dd0b9e8668e… 2023-08-31 2023-09-15
DOMAIN hironchk.com 2023-08-31 2023-09-15
HASH 5305b8969b33549b6bd4b68a3f9a2db… 2023-08-31 2023-09-14
HASH 454cfe3be695d0a387d7877c11d3b22… 2023-08-31 2023-09-14
URL https://syra.forumcommunity.net… 2023-08-31 2023-09-14
DOMAIN autoit-script.ru 2023-08-31 2023-09-14
DOMAIN syra.forumcommunity.net 2023-08-31 2023-09-14
HASH 614dda72d95b5dfd732916aec0662598 2023-09-01 2023-09-01

Related Actors

Related Reports

« Back