Warning Against Distribution of Malware Impersonating a Public Organization (LNK)

2023-11-14 Ahnlab

https://asec.ahnlab.com/en/59042/

Thumbnail for Warning Against Distribution of Malware Impersonating a Public Organization (LNK)

ASEC observed malicious HTML and LNK files impersonating a public organization and using honorarium themed HWP documents as lures for people in Korean reunification and national security fields. Running the LNK opens a legitimate HWP file while dropping obfuscated VBS or PowerShell components that change registry settings, collect user information, and fetch additional scripts. One chain downloads TutRAT and fileless payloads, then supports keylogging, browser credential theft, screenshots, and command execution. The source ties the activity to a previously observed actor through similar operation methods and C2 format, including 165.154.230[.]24:8020 and related Korean web paths.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 64dee04b6e6404c14d10971adf35c3a7 2023-11-09 2024-04-17
HASH eb614c99614c3365bdc926a73ef7a492 2023-11-09 2024-04-17
HASH fb5aec165279015f17b29f9f2c730976 2023-11-09 2024-04-17
HASH b70bc31b537caf411f97a991d8292c5a 2023-11-09 2024-04-17
IPv4 165.154.230.24 2023-11-09 2024-04-17
HASH de7cd0de5372e7801dab5aafd9c19148 2023-11-09 2023-11-14
HASH 5e5a87d0034e80e6b86a64387779dc2e 2023-11-09 2023-11-14
HASH 209ac4185dfc1e4d72c035ecb7f98eac 2023-11-09 2023-11-14
HASH 0040aa9762c2534ac44d9a6ae7024d15 2023-11-09 2023-11-14
HASH d00aa4b1a3cd9373d49c023580711170 2023-11-09 2023-11-14
HASH 40b7c3bced2975d70359a07c4f110f18 2023-11-09 2023-11-14

Related Actors

Related Reports

« Back