Red Eyes Hacking Group 상세 분석

2018-04-03 Ahnlab Red Eyes Hacking Group Detailed Analysis

http://download.ahnlab.com/kr/site/library/[Report]Red_Eyes_Hacking_Group_kor.pdf

Attachments

ReportRed_Eyes_Hacking_Group_kor.pdf (1 MB)

Thumbnail for Red Eyes Hacking Group 상세 분석

AhnLab profiles the Red Eyes group, also known as Geumseong121, Group 123, ScarCruft, APT37, Reaper, and Ricochet Chollima, as a cluster targeting defectors, North Korean human-rights activists, North Korea researchers, journalists, and some military-themed lures. The group commonly delivered malicious documents by email or mobile messenger, using HWP EPS exploitation, embedded VBS or EXE files, MS Office documents, DDE, and a Flash Player zero-day later identified as CVE-2018-4878. Malware families described in the report include Reloader or DocPrint loaders, Reloaderx information stealers and downloaders, the Redoor or DogCall backdoor, and a wiper that damages hard disks and displays an "Are you Happy?" message after reboot. AhnLab also notes distinctive PDB paths and strings such as First, Happy, Work, and pad-2 artifacts, using them to discuss possible links to earlier 2015-2016 activity including Operation ProgamsByMe.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7ca1e08fc07166a440576d1af0a15bb1 2018-04-03 2023-05-23
HASH 44bdeb6c0af7c36a08c64e31ceadc63c 2018-04-03 2023-05-23
HASH 6cec7de9d4797895775e2add9d6855ba 2018-04-03 2018-08-14
HASH 9cd11aa7872f9cba98264113d3d72893 2018-04-03 2018-08-14
HASH f793deeee9dc4235d228e68d27057dcc 2018-04-03 2018-08-14
HASH 89c3254aa577d3788f0f402fe6e5a855 2018-04-03 2018-08-14
HASH 8b55d52b12cf319d9785ad8eeeade5ea 2018-04-03 2018-08-14
HASH 9f1e60e0c794aa3f3bdf8a6645ccabdc 2018-04-03 2018-08-14
HASH f0a5385d0d9f7c546b25a7448ca5b1c9 2018-04-03 2018-08-14
HASH 2f0492f53d348bea993b7ae5983508a6 2018-04-03 2018-08-14
HASH 06ae5d62d56f21cd2676989743b9626c 2018-04-03 2018-08-14
HASH 2fdbb9a500143a2dd3d226a1cc3e45b5 2018-04-03 2018-08-14
HASH 49d30adaab769fbea2ef69e09c6598c5 2018-04-03 2018-08-14
HASH 9ac2ffd3f1cea2e01ed77c2e7b4a29e7 2018-04-03 2018-08-14
HASH d00e3196bc847e63fc4b255e8ab06d1c 2018-04-03 2018-08-14
HASH f613c9276d0deb19d0959aa2fbfc737c 2018-04-03 2018-08-14
DOMAIN byline.network 2018-04-03 2018-08-14
DOMAIN ush.co.kr 2018-04-03 2018-08-14
HASH 0ff0f3f0722dd122a0f5c3d4c7752675 2018-02-27 2018-08-14
HASH fc0a9850f7b6a91f7757d64c86cfc141 2018-02-27 2018-08-14
HASH 42f216cc32cf2b14e6daea0816da8c50 2018-04-03 2018-04-03
HASH 5ef03b48b4ae68c572028c72572444d2 2018-04-03 2018-04-03
DOMAIN biz.khan.co.kr 2018-04-03 2018-04-03

Related Actors

Related Reports

« Back