Operation ControlPlug: APT Attack Campaign abusing MSC file

2024-06-13 NTTSecurity

https://jp.security.ntt/tech_blog/controlplug-en

Thumbnail for Operation ControlPlug: APT Attack Campaign abusing MSC file

NTT notes that Kimsuky abuse of MSC files had been reported since April 2024, placing Microsoft Common Console documents among techniques already adopted by multiple APT groups. The detailed case in the excerpt is DarkPeony’s Operation ControlPlug rather than a Kimsuky intrusion, but it shows how an MSC Console Taskpad link can launch PowerShell when a user clicks a disguised interface element. In that chain, PowerShell downloads an MSI package, a legitimate EXE performs DLL side-loading, a DAT file is decoded, and PlugX is launched. The campaign’s MSI delivery sites sometimes used Cloudflare restrictions, which NTT assesses may have been intended to block researchers or automated analysis while still allowing target access. For DPRK-focused tracking, the supported finding is limited to Kimsuky’s reported use of MSC files, with the DarkPeony chain providing context on why MSC abuse is operationally significant.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e81982e40ee5aaed85817343464d621… 2024-06-05 2024-06-13
HASH 8c9e1f17e82369d857e5bf3c41f0609… 2024-06-05 2024-06-13
HASH 1cbf860e99dcd2594a9de3c616ee86c… 2024-06-05 2024-06-13
HASH 54549745868b27f5e533a99b3c10f29… 2024-06-05 2024-06-13
HASH f0aa5a27ea01362dce9ced3685961d5… 2024-06-05 2024-06-13
DOMAIN lebohdc.com 2024-06-05 2024-06-13
DOMAIN shreyaninfotech.com 2024-06-05 2024-06-13
DOMAIN lifeyomi.com 2024-06-05 2024-06-13
DOMAIN gulfesolutions.com 2024-06-05 2024-06-13
DOMAIN buyinginfo.org 2024-06-05 2024-06-13
DOMAIN versaillesinfo.com 2024-06-05 2024-06-13
DOMAIN profilepimpz.com 2024-06-03 2024-06-13

Related Reports

« Back