Story of the ‘Phisherman’ - Dissecting Phishing Techniques of CloudDragon APT
2021-05-28 • Team T5 •
Attachments
TeamT5’s HITB slides dissect CloudDragon “Phisherman” tradecraft, focusing on phishing infrastructure rather than a single intrusion victim. The material shows email delivery tooling, including PHPMailer on compromised C2 sites, target-account lists, and tokenized phishing URLs that log victim data and redirect users to decoy content. It also describes evolutions from traditional credential pages to proxy-mirror and phishing-bot workflows that use encoded parameters, mobile detection, and decrypt-and-redirect logic to mimic webmail sessions. The malware section highlights AppleSeed/AutoUpdate capabilities, including command execution, DLL loading with regsvr32, in-memory DLL execution, command polling, upload, deletion, and upgrade endpoints.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | phpurlproxy.kr | 2021-05-28 | 2021-05-28 |