Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

2024-07-01 Ahnlab

https://asec.ahnlab.com/en/67558/

Thumbnail for Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

ASEC observed attacks against Korean defense and manufacturing organizations in which a threat actor abused a Korean ERP solution and compromised Windows IIS web servers to deploy Xctdoor and XcLoader. The ERP case resembles earlier Andariel tradecraft from 2017, where a malicious routine was inserted into an ERP updater to distribute the HotCroissant backdoor, but the recent activity is described as involving an unidentified threat actor. Xctdoor is a Go-based DLL backdoor executed through Regsvr32.exe, injected into normal processes, and persisted through files under a Microsoft Edge package path and a startup shortcut. Its capabilities include system profiling, command execution, screenshot capture, keylogging, clipboard logging, drive information collection, and HTTP C2 using Mersenne Twister and Base64-based encryption. The web-server cases involved XcLoader installation, command execution consistent with possible web-shell access, and Ngrok use to expose RDP access, making the activity significant for tracking ERP supply-chain abuse and DPRK-linked Andariel-adjacent techniques in Korean enterprises.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9bbde4484821335d98b41b44f93276e8 2024-06-24 2024-07-01
HASH 235e02eba12286e74e886b6c99e46fb7 2024-06-24 2024-07-01
HASH f24627f46ec64cae7a6fa9ee312c43d7 2024-06-24 2024-07-01
HASH 41d5d25de0ca0fdc54c24c484f9f8f55 2024-06-24 2024-07-01
HASH 2e325935b2d1d0a82e63ff2876482956 2024-06-24 2024-07-01
HASH 9a580aaaa3e79b6f19a2c70e89b016e3 2024-06-24 2024-07-01
HASH 396bee51c7485c3a0d3b044a9ceb6487 2024-06-24 2024-07-01
HASH 375f1cc32b6493662a78720c7d905bc3 2024-06-24 2024-07-01
HASH 6928fab25ac1255fbd8d6c1046653919 2024-06-24 2024-07-01
HASH ab8675b4943bc25a51da66565cfc8ac8 2024-06-24 2024-07-01
HASH b96b98dede8a64373b539f94042bdb41 2024-06-24 2024-07-01
HASH a42ae44761ce3294ce0775fe384d97b6 2024-06-24 2024-07-01
HASH d787a33d76552019becfef0a4af78a11 2024-06-24 2024-07-01
HASH d938201644aac3421df7a3128aa88a53 2024-06-24 2024-07-01
HASH e554b1be8bab11e979c75e2c2453bc6a 2024-06-24 2024-07-01
HASH 54d5be3a4eb0e31c0ba7cb88f0a8e720 2024-06-24 2024-07-01
HASH ad96a8f22faab8b9c361cfccc381cd28 2024-06-24 2024-07-01
HASH 11465d02b0d7231730f3c4202b0400b8 2024-06-24 2024-07-01
HASH d852c3d06ef63ea6c6a21b0d1cdf14d4 2024-06-24 2024-07-01
HASH b43a7dcfe53a981831ae763a9a5450fd 2024-06-24 2024-07-01
HASH 4f5e5a392b8a3e0cb32320ed1e8d0604 2024-06-24 2024-07-01
HASH 09a5069c9cc87af39bbb6356af2c1a36 2024-06-24 2024-07-01
URL http://www.jikji.pe.kr/xe/files… 2024-06-24 2024-07-01
URL http://beebeep.info/index.php 2024-06-24 2024-07-01
DOMAIN beebeep.info 2024-06-24 2024-07-01
IPv4 195.50.242.110 2024-06-24 2024-07-01

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

2024-07-25 • 48% Match
#Andariel #Maui #MoneyLaundering #ArkansasHealthcare #CaliforniaDefense #ChineseEnergy #ColoradoMedical #ConnecticutHealthcare #FloridaHospital #KansasHospital #MassachusettsDefense #MichiganDefense #NASA #OregonDefense #RandolphAirForce #RobinsAirForce #SouthKoreanManufacturing #TaiwaneseDefense
Shares tag: Andariel • Published within a month
« Back