Targeted APT Activity: BABYSHARK Is Out for Blood
2022-03-01 • Huntress •
https://www.huntress.com/blog/targeted-apt-activity-babyshark-is-out-for-blood
Huntress investigated targeted DPRK-backed APT activity against a nuclear or national-security think tank environment and identified BABYSHARK tradecraft in the intrusion. The actor maintained persistence through a scheduled task named GoogleUpdater that launched qwert.vbs via wscript.exe, then retrieved obfuscated content from a Google Drive page. The malware used johnbegin/johnend-style delimiters and staged normal.crp for later deobfuscation and VBScript execution, matching previously reported North Korean BABYSHARK techniques. The incident matters because the variant was customized to the victim environment, showing focused espionage rather than commodity malware deployment.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5b31d65b0607ae3de40ff8376bb83f3… | 2022-03-01 | 2022-03-01 |
| HASH | c86d6e9dfc79bdf29f0826327992f8c… | 2022-03-01 | 2022-03-01 |
| HASH | def0975728fc5da61c022bb62b7160e… | 2022-03-01 | 2022-03-01 |
| HASH | bf82675bac2cd574fa8b87659217bff… | 2022-03-01 | 2022-03-01 |
| HASH | c327631a212e4a9681e3cf1574c500c… | 2022-03-01 | 2022-03-01 |
| HASH | d41c943fd5ffacde74f487df6a43b72… | 2022-03-01 | 2022-03-01 |
| HASH | 2ad3266331e405677c68bb43c490467… | 2022-03-01 | 2022-03-01 |
| HASH | e08fe0b287b4d112514276c2b102b9c… | 2022-03-01 | 2022-03-01 |
| HASH | e314b40449b7b9b84f20f49f8988851… | 2022-03-01 | 2022-03-01 |
| URL | https://hodbeast.com/silver/upl… | 2022-03-01 | 2022-03-01 |
| URL | http://beastmodser.club/sil/030… | 2022-03-01 | 2022-03-01 |
| URL | https://beastmodser.club/sil/03… | 2022-03-01 | 2022-03-01 |
| URL | https://frebough.com/onedrive/w… | 2022-03-01 | 2022-03-01 |
| DOMAIN | frebough.com | 2022-03-01 | 2022-03-01 |
| DOMAIN | beastmodser.club | 2022-03-01 | 2022-03-01 |
| DOMAIN | hodbeast.com | 2022-03-01 | 2022-03-01 |