Piece of dragon's scales
2021-12-30 • kino •
A Korean malware-analysis post tracks ongoing Kimsuky/Thallium activity using the GoldDragon/BravePrince cluster, noting a newer sample that keeps the usual daum-mail information-theft behavior while adding encoded DLL and API-name resolution. The author also describes a related information-stealer module that collects system, network, process, file-list, and browser credential data into an AppData working directory and appears designed to be launched by another component. A third case links the same encoded-string intelligence pivot to a .NET dropper that deploys privilege-elevation tooling, disables Windows Defender, installs a Quasar RAT-based payload, and persists through scheduled tasks or Run keys. Representative infrastructure and indicators include blog.daum[.]net/casalesmedia/pages/category, 222.122.79.232 on ports 8080 and 443, and hashes for the analyzed samples.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e8bef41ed7d0704d9206880ee0f30b5… | 2021-12-30 | 2021-12-30 |
| HASH | 3a7355417ebfdb5067582916bbaf0f15 | 2021-12-30 | 2021-12-30 |
| HASH | 8edfa086de4dfdc93c0551bbb08cd5a8 | 2021-12-30 | 2021-12-30 |
| HASH | 4b1b5bed35bc676e835de14ee033339… | 2021-12-30 | 2021-12-30 |
| HASH | 237deba138355bfb448e74bfb68fc86… | 2021-12-30 | 2021-12-30 |
| HASH | e11e2425c62f34ebb3f640baeefb67d5 | 2021-12-30 | 2021-12-30 |
| HASH | 322ad36bf0db8244b64e2d3afc1ccf5… | 2021-12-30 | 2021-12-30 |
| HASH | 7dc6f8aaaf4431c365564a51dd37c14… | 2021-12-30 | 2021-12-30 |
| HASH | 0cf7e1268e8652d841b7bda784707e4… | 2021-12-30 | 2021-12-30 |
| HASH | 51a92bd57ece4a107dacabf2639b6fa… | 2021-12-30 | 2021-12-30 |
| HASH | c3885f3c1001a53eb4fbbb4b5f42163e | 2021-12-30 | 2021-12-30 |
| HASH | e647b3366dc836c1f63bdc5ba2aef3a9 | 2021-12-30 | 2021-12-30 |
| HASH | 3903958eb28632aa58e455eb87482d1… | 2021-12-30 | 2021-12-30 |
| HASH | a7b0711b45081768817e85d6fc76e23… | 2021-12-30 | 2021-12-30 |
| IPv4 | 222.122.79.232 | 2021-12-30 | 2021-12-30 |
| IPv4 | 14.47.189.243 | 2021-12-30 | 2021-12-30 |
| HASH | 5e3907e9e2ed8ff12bb4e96b52401d8… | 2021-11-10 | 2021-12-30 |