Silent RIFLE: How to take control of all your information systems
2017-01-30 • Hackcon •
Attachments
0520-20Kwak.pdf (13 MB)
Kyoung-Ju Kwak’s HackCon material links the RIFLE campaign to Lazarus Group context from Operation Blockbuster and South Korean incidents including DarkSeoul, financial-sector attacks, and defense-sector spearphishing. The RIFLE malware family is described as including a downloader, sniffer, and server component, with infected hosts creating guifx.exe, using mutexes such as ASDASDASDSA, collecting user, host, OS, and network adapter data, and communicating with C2 servers including 192.99.223.115 and compromised Korean infrastructure. The campaign abused stolen Initech code-signing certificates and is correlated with an ADEX-themed macro lure targeting military and defense organizations such as LIG Nexone, Samsung Thales, Samsung Techwin, Agency for Defense Development, Doosan DST, and Hanwha Defense. The slides also describe exploitation of third-party Korean security and management products, including Nicstech DLP and TCO!Stream, to move through supplier and victim environments, reinforcing the operational risk of trusted software providers in South Korean financial, defense, and conglomerate networks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 192.99.223.115 | 2016-02-23 | 2020-04-16 |
| IPv4 | 165.194.123.67 | 2016-02-23 | 2020-04-16 |
| HASH | 62fdf4822431d4c82b78e602ab3558ad | 2017-01-30 | 2017-01-30 |
| HASH | bb710db1c03ebc4f8d6ebb8b8577ee78 | 2017-01-30 | 2017-01-30 |
| HASH | 33e09cf92dd8ab4f75dac20e088a5709 | 2017-01-30 | 2017-01-30 |
| HASH | eca2dfaa11ed41f119346e333b5d8461 | 2017-01-30 | 2017-01-30 |
| HASH | 5ca4562a5bfa15417707d3168161cb23 | 2017-01-30 | 2017-01-30 |
| HASH | ee778be503fda770ee2f40e51edfd595 | 2017-01-30 | 2017-01-30 |
| HASH | c2a171716ff72b8c8965dfb3cd3eccff | 2017-01-30 | 2017-01-30 |
| HASH | a1f92b84614d7f07ab84c7a97675b299 | 2017-01-30 | 2017-01-30 |
| HASH | 741fadda07d9c2e41d6d8b0f2e91bc5e | 2017-01-30 | 2017-01-30 |
| HASH | 275b7af66726950a895fbd74c6227cab | 2017-01-30 | 2017-01-30 |
| URL | https://kevinchen.co/blog/insta… | 2017-01-30 | 2017-01-30 |
| DOMAIN | kevinchen.co | 2017-01-30 | 2017-01-30 |
| DOMAIN | caccm.org | 2017-01-30 | 2017-01-30 |
| IPv4 | 203.241.248.108 | 2017-01-30 | 2017-01-30 |
| IPv4 | 165.194.117.35 | 2017-01-30 | 2017-01-30 |
| IPv4 | 158.69.115.115 | 2017-01-30 | 2017-01-30 |
| IPv4 | 124.139.210.45 | 2017-01-30 | 2017-01-30 |
| IPv4 | 175.117.144.67 | 2017-01-30 | 2017-01-30 |