Operation Kabar Cobra: Kimsuky 공격 그룹의 최신 타깃 공격 사례 분석

2019-03-04 Ahnlab Operation Kabar Cobra: Analysis of the latest targeted attacks by the Kimsuky attack group

http://download.ahnlab.com/kr/site/library/[Analysis_Report]Operation_Kabar_Cobra.pdf

Attachments

Analysis_ReportOperation_Kabar_Cobra.pdf (6 MB)

Thumbnail for Operation Kabar Cobra: Kimsuky 공격 그룹의 최신 타깃 공격 사례 분석

AhnLab attributes Operation Kabar Cobra to activity suspected of being linked to Kimsuky, including January 2019 malware sent to Ministry of Unification reporters and other recent targeting of military, media, finance, cryptocurrency, and related sectors. The attacks used files disguised as Hangul documents with double extensions and long spaces, often packed as WinRAR SFX archives containing decoy HWP/PDF content and malicious WSF scripts. The scripts retrieved C2 configuration from the attacker’s Google Drive, downloaded additional malware such as Freedom.dll/AhnLabMon.dll and list.dll/Cobra.dll, and supported command execution, file transfer, updates, and log transmission with Base64-encoded C2 traffic. Cobra.dll collected drive, hardware, folder, and file-list information and sent it to C2, enabling data theft from real targets or anti-analysis actions when the attacker recognized a research environment. The report is important because it documents Kimsuky-linked adaptation around the U.S.–North Korea summit period and shows flexible C2 management, targeted decoys, and hands-on operator commands.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 185.224.138.29 2019-03-04 2020-11-12
DOMAIN my-homework.890m.com 2019-01-30 2020-11-12
HASH b994bd755e034d2218f8a3f70e91a165 2019-03-04 2020-04-08
HASH 9d685308d3125e14287ecb7fbe5fcd37 2019-03-04 2020-04-08
HASH 48d9e625ea3efbcbef3963c8714544a7 2019-02-07 2019-11-18
HASH f22db1e3ea74af791e34ad5aa0297664 2019-03-04 2019-10-04
HASH 4de21c3af64b3b605446278de92dfff4 2019-03-04 2019-10-04
HASH b02f3881321f0912b2ae3f27498c448f 2019-03-04 2019-08-29
HASH 11fc4829c2fff9fb240acbd71c60fc67 2019-03-04 2019-08-29
HASH dc1196876d9a59ab477ebc62d07a255e 2019-03-04 2019-03-04
HASH bb42e6649d927899c816cc04c2bffc06 2019-03-04 2019-03-04
HASH 6106449779d453be4ae28d89f207e921 2019-03-04 2019-03-04
HASH ba89337af43f0b07a35cc892ac95112a 2019-03-04 2019-03-04
HASH 66b73fba4e47b3184edd75b0ce9cf928 2019-03-04 2019-03-04
HASH 874c0ec36be15fe3403f3abad6ecea75 2019-03-04 2019-03-04
HASH 08523230e221246bb59cde7c3e8363c7 2019-03-04 2019-03-04
HASH cd705902ea42d0de2a8456b055c3bb87 2019-03-04 2019-03-04
HASH 74c3011b6980bea23d119822d979a364 2019-03-04 2019-03-04
HASH 1dfe826f71c20ff04987a9160c177e46 2019-03-04 2019-03-04
HASH 2fdf23367c604511d019a6914c50bc0b 2019-03-04 2019-03-04
HASH 566cc6129dc887629a7131821c7547e5 2019-03-04 2019-03-04
HASH a45ba001c3abee03bda49c6816d9a17c 2019-03-04 2019-03-04
HASH 2f26f3a883aeca9a11769664fc7d4750 2019-03-04 2019-03-04
HASH 02dae3046d1669a55785ba935b0e3f0b 2019-03-04 2019-03-04
HASH b49bbc11ed000211a5af7eb35f596886 2019-03-04 2019-03-04
HASH b7359ae1a83323d3671e7c3a63ce7bf1 2019-03-04 2019-03-04
HASH 8332be776617364c16868c1ad6b4efe7 2019-03-04 2019-03-04
HASH aea8d3002132094a58d5189a8e886cf8 2019-03-04 2019-03-04
HASH 0eb739c8faf77dae0546ff447ad06038 2019-03-04 2019-03-04
HASH 1a082a388a285e7fc4541124794f3910 2019-03-04 2019-03-04
HASH 9c3396aa94083916227201bf1396a2ca 2019-03-04 2019-03-04
HASH 71ec829db01818d305552ec4ebb1c258 2019-03-04 2019-03-04
HASH 242c31d0ce2109fdface788663e90f49 2019-03-04 2019-03-04
HASH 95410a32a76aecb099af53255bb90737 2019-03-04 2019-03-04
HASH 20301fdd013c836039b8cfe0d100a1d7 2019-03-04 2019-03-04
HASH 0a50827a4897a43a882c8d3c691d943d 2019-03-04 2019-03-04
EMAIL [email protected] 2019-03-04 2019-03-04
DOMAIN homework.890m.com 2019-03-04 2019-03-04
DOMAIN brave.ru 2019-03-04 2019-03-04
EMAIL [email protected] 2019-01-30 2019-03-04
HASH 54783422cfd7029a26a3f3f5e9087d8a 2014-12-10 2019-03-04
HASH ab73b1395938c48d62b7eeb5c9f3409d 2013-09-11 2019-03-04

Related Actors

Related Reports

« Back