Operation ControlPlug: APT Attack Campaign abusing MSC file
2024-06-13 • NTTSecurity •
NTT notes that Kimsuky abuse of MSC files had been reported since April 2024, placing Microsoft Common Console documents among techniques already adopted by multiple APT groups. The detailed case in the excerpt is DarkPeony’s Operation ControlPlug rather than a Kimsuky intrusion, but it shows how an MSC Console Taskpad link can launch PowerShell when a user clicks a disguised interface element. In that chain, PowerShell downloads an MSI package, a legitimate EXE performs DLL side-loading, a DAT file is decoded, and PlugX is launched. The campaign’s MSI delivery sites sometimes used Cloudflare restrictions, which NTT assesses may have been intended to block researchers or automated analysis while still allowing target access. For DPRK-focused tracking, the supported finding is limited to Kimsuky’s reported use of MSC files, with the DarkPeony chain providing context on why MSC abuse is operationally significant.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e81982e40ee5aaed85817343464d621… | 2024-06-05 | 2024-06-13 |
| HASH | 8c9e1f17e82369d857e5bf3c41f0609… | 2024-06-05 | 2024-06-13 |
| HASH | 1cbf860e99dcd2594a9de3c616ee86c… | 2024-06-05 | 2024-06-13 |
| HASH | 54549745868b27f5e533a99b3c10f29… | 2024-06-05 | 2024-06-13 |
| HASH | f0aa5a27ea01362dce9ced3685961d5… | 2024-06-05 | 2024-06-13 |
| DOMAIN | lebohdc.com | 2024-06-05 | 2024-06-13 |
| DOMAIN | shreyaninfotech.com | 2024-06-05 | 2024-06-13 |
| DOMAIN | lifeyomi.com | 2024-06-05 | 2024-06-13 |
| DOMAIN | gulfesolutions.com | 2024-06-05 | 2024-06-13 |
| DOMAIN | buyinginfo.org | 2024-06-05 | 2024-06-13 |
| DOMAIN | versaillesinfo.com | 2024-06-05 | 2024-06-13 |
| DOMAIN | profilepimpz.com | 2024-06-03 | 2024-06-13 |