Warning Against Distribution of Malware Impersonating a Public Organization (LNK)
2023-11-14 • Ahnlab •
ASEC observed malicious HTML and LNK files impersonating a public organization and using honorarium themed HWP documents as lures for people in Korean reunification and national security fields. Running the LNK opens a legitimate HWP file while dropping obfuscated VBS or PowerShell components that change registry settings, collect user information, and fetch additional scripts. One chain downloads TutRAT and fileless payloads, then supports keylogging, browser credential theft, screenshots, and command execution. The source ties the activity to a previously observed actor through similar operation methods and C2 format, including 165.154.230[.]24:8020 and related Korean web paths.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 64dee04b6e6404c14d10971adf35c3a7 | 2023-11-09 | 2024-04-17 |
| HASH | eb614c99614c3365bdc926a73ef7a492 | 2023-11-09 | 2024-04-17 |
| HASH | fb5aec165279015f17b29f9f2c730976 | 2023-11-09 | 2024-04-17 |
| HASH | b70bc31b537caf411f97a991d8292c5a | 2023-11-09 | 2024-04-17 |
| IPv4 | 165.154.230.24 | 2023-11-09 | 2024-04-17 |
| HASH | de7cd0de5372e7801dab5aafd9c19148 | 2023-11-09 | 2023-11-14 |
| HASH | 5e5a87d0034e80e6b86a64387779dc2e | 2023-11-09 | 2023-11-14 |
| HASH | 209ac4185dfc1e4d72c035ecb7f98eac | 2023-11-09 | 2023-11-14 |
| HASH | 0040aa9762c2534ac44d9a6ae7024d15 | 2023-11-09 | 2023-11-14 |
| HASH | d00aa4b1a3cd9373d49c023580711170 | 2023-11-09 | 2023-11-14 |
| HASH | 40b7c3bced2975d70359a07c4f110f18 | 2023-11-09 | 2023-11-14 |