Silent RIFLE: How to take control of all your information systems

2017-01-30 Hackcon

https://hackcon.org/uploads/327/05%20-%20Kwak.pdf

Attachments

0520-20Kwak.pdf (13 MB)

Kyoung-Ju Kwak’s HackCon material links the RIFLE campaign to Lazarus Group context from Operation Blockbuster and South Korean incidents including DarkSeoul, financial-sector attacks, and defense-sector spearphishing. The RIFLE malware family is described as including a downloader, sniffer, and server component, with infected hosts creating guifx.exe, using mutexes such as ASDASDASDSA, collecting user, host, OS, and network adapter data, and communicating with C2 servers including 192.99.223.115 and compromised Korean infrastructure. The campaign abused stolen Initech code-signing certificates and is correlated with an ADEX-themed macro lure targeting military and defense organizations such as LIG Nexone, Samsung Thales, Samsung Techwin, Agency for Defense Development, Doosan DST, and Hanwha Defense. The slides also describe exploitation of third-party Korean security and management products, including Nicstech DLP and TCO!Stream, to move through supplier and victim environments, reinforcing the operational risk of trusted software providers in South Korean financial, defense, and conglomerate networks.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 192.99.223.115 2016-02-23 2020-04-16
IPv4 165.194.123.67 2016-02-23 2020-04-16
HASH 62fdf4822431d4c82b78e602ab3558ad 2017-01-30 2017-01-30
HASH bb710db1c03ebc4f8d6ebb8b8577ee78 2017-01-30 2017-01-30
HASH 33e09cf92dd8ab4f75dac20e088a5709 2017-01-30 2017-01-30
HASH eca2dfaa11ed41f119346e333b5d8461 2017-01-30 2017-01-30
HASH 5ca4562a5bfa15417707d3168161cb23 2017-01-30 2017-01-30
HASH ee778be503fda770ee2f40e51edfd595 2017-01-30 2017-01-30
HASH c2a171716ff72b8c8965dfb3cd3eccff 2017-01-30 2017-01-30
HASH a1f92b84614d7f07ab84c7a97675b299 2017-01-30 2017-01-30
HASH 741fadda07d9c2e41d6d8b0f2e91bc5e 2017-01-30 2017-01-30
HASH 275b7af66726950a895fbd74c6227cab 2017-01-30 2017-01-30
URL https://kevinchen.co/blog/insta… 2017-01-30 2017-01-30
DOMAIN kevinchen.co 2017-01-30 2017-01-30
DOMAIN caccm.org 2017-01-30 2017-01-30
IPv4 203.241.248.108 2017-01-30 2017-01-30
IPv4 165.194.117.35 2017-01-30 2017-01-30
IPv4 158.69.115.115 2017-01-30 2017-01-30
IPv4 124.139.210.45 2017-01-30 2017-01-30
IPv4 175.117.144.67 2017-01-30 2017-01-30

Related Reports

« Back