Story of the ‘Phisherman’ - Dissecting Phishing Techniques of CloudDragon APT

2021-05-28 Team T5

https://conference.hitb.org/hitbsecconf2021ams/materials/D2T1%20-%20The%20Phishermen%20-%20Dissecting%20Phishing%20Techniques%20of%20CloudDragon%20APT%20-%20Linda%20Kuo%20&Zih-Cing%20Liao%20.pdf

Attachments

D2T120-20The20Phishermen20-20Dissecting20Phishing20Techniques20of2_niDtzJ4.pdf (12 MB)

Thumbnail for Story of the ‘Phisherman’ - Dissecting Phishing Techniques of CloudDragon APT

TeamT5’s HITB slides dissect CloudDragon “Phisherman” tradecraft, focusing on phishing infrastructure rather than a single intrusion victim. The material shows email delivery tooling, including PHPMailer on compromised C2 sites, target-account lists, and tokenized phishing URLs that log victim data and redirect users to decoy content. It also describes evolutions from traditional credential pages to proxy-mirror and phishing-bot workflows that use encoded parameters, mobile detection, and decrypt-and-redirect logic to mimic webmail sessions. The malware section highlights AppleSeed/AutoUpdate capabilities, including command execution, DLL loading with regsvr32, in-memory DLL execution, command polling, upload, deletion, and upgrade endpoints.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN phpurlproxy.kr 2021-05-28 2021-05-28

Related Actors

Related Reports

« Back