The ink-stained trail of GOLDBACKDOOR

2022-04-21 Stairwell

https://assets.stairwell.com/hubfs/Marketing-Assets/Stairwell-threat-report-The-ink-stained-trail-of-GOLDBACKDOOR.pdf

Attachments

Stairwell-threat-report-The-ink-stained-trail-of-GOLDBACKDOOR_Fm70I4B.pdf (407 KB)

Stairwell analyzed a GOLDBACKDOOR deployment chain from malicious artifacts NK News received in a spear-phishing campaign targeting journalists focused on the DPRK. The campaign delivered a ZIP containing a large Windows shortcut named “Kang Min-chol Edits 2.lnk,” which opened a decoy document while running PowerShell to stage additional code. Stairwell assessed with medium-high confidence that GOLDBACKDOOR is a successor to, or used alongside, BLUELIGHT malware attributed to APT37/Ricochet Chollima, based on technical overlaps and the impersonation of DPRK-focused media. The infrastructure included a dailynk.us domain likely chosen to mimic Daily NK, and the multi-stage design allowed the actor to separate initial infection from final payload deployment.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 485246b411ef5ea9e903397a5490d10… 2022-04-21 2025-04-01
URL https://1drv.ms/u/s!Ar9zfrwxWWE… 2022-04-21 2022-04-27
YARA NK_GOLDBACKDOOR_Main 2022-04-21 2022-04-21
YARA NK_GOLDBACKDOOR_generic_shellco… 2022-04-21 2022-04-21
YARA NK_GOLDBACKDOOR_injected_shellc… 2022-04-21 2022-04-21
YARA NK_GOLDBACKDOOR_inital_shellcode 2022-04-21 2022-04-21
YARA NK_GOLDBACKDOOR_obf_payload 2022-04-21 2022-04-21
YARA NK_GOLDBACKDOOR_LNK_payload 2022-04-21 2022-04-21
YARA NK_GOLDBACKDOOR_LNK 2022-04-21 2022-04-21
HASH 9eddd99db6f5a7791f7e446792f04b3… 2022-04-21 2022-04-21
HASH 18c9fd4f781789cd15cee4fcb18fa98… 2022-04-21 2022-04-21
HASH 94ca32c0a3002574d7ea1bef094146a… 2022-04-21 2022-04-21
HASH c5369c2ce7f33d6cd209cd61226a063… 2022-04-21 2022-04-21
HASH 120ca851663ef0ebef585d716c9e2ba… 2022-04-21 2022-04-21
URL https://api.onedrive.com/v1.0/s… 2022-04-21 2022-04-21
URL https://main.dailynk.us/regex?i… 2022-04-21 2022-04-21
DOMAIN main.dailynk.us 2022-04-21 2022-04-21
IPv4 142.93.201.77 2022-04-21 2022-04-21

Related Actors

Related Reports

« Back