Targeted APT Activity: BABYSHARK Is Out for Blood

2022-03-01 Huntress

https://www.huntress.com/blog/targeted-apt-activity-babyshark-is-out-for-blood

Thumbnail for Targeted APT Activity: BABYSHARK Is Out for Blood

Huntress investigated targeted DPRK-backed APT activity against a nuclear or national-security think tank environment and identified BABYSHARK tradecraft in the intrusion. The actor maintained persistence through a scheduled task named GoogleUpdater that launched qwert.vbs via wscript.exe, then retrieved obfuscated content from a Google Drive page. The malware used johnbegin/johnend-style delimiters and staged normal.crp for later deobfuscation and VBScript execution, matching previously reported North Korean BABYSHARK techniques. The incident matters because the variant was customized to the victim environment, showing focused espionage rather than commodity malware deployment.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5b31d65b0607ae3de40ff8376bb83f3… 2022-03-01 2022-03-01
HASH c86d6e9dfc79bdf29f0826327992f8c… 2022-03-01 2022-03-01
HASH def0975728fc5da61c022bb62b7160e… 2022-03-01 2022-03-01
HASH bf82675bac2cd574fa8b87659217bff… 2022-03-01 2022-03-01
HASH c327631a212e4a9681e3cf1574c500c… 2022-03-01 2022-03-01
HASH d41c943fd5ffacde74f487df6a43b72… 2022-03-01 2022-03-01
HASH 2ad3266331e405677c68bb43c490467… 2022-03-01 2022-03-01
HASH e08fe0b287b4d112514276c2b102b9c… 2022-03-01 2022-03-01
HASH e314b40449b7b9b84f20f49f8988851… 2022-03-01 2022-03-01
URL https://hodbeast.com/silver/upl… 2022-03-01 2022-03-01
URL http://beastmodser.club/sil/030… 2022-03-01 2022-03-01
URL https://beastmodser.club/sil/03… 2022-03-01 2022-03-01
URL https://frebough.com/onedrive/w… 2022-03-01 2022-03-01
DOMAIN frebough.com 2022-03-01 2022-03-01
DOMAIN beastmodser.club 2022-03-01 2022-03-01
DOMAIN hodbeast.com 2022-03-01 2022-03-01

Related Reports

« Back