Zoom 접속 정보로 위장한 ReconShark

2023-08-21 Hauri ReconShark disguised as Zoom access information

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=53

Attachments

2023-08-21_ìì_ëì_ë³ê³ìZoom_ìì_ìë³ë_ììí_ReconShark.pdf (702 KB)

Hauri reported a Kimsuky malware family called ReconShark that used Zoom meeting-information lures against organizations and individuals handling North Korea-related information. The malware displayed a decoy Zoom document from attacker infrastructure, collected battery and process information from the infected PC, and sent it to command-and-control infrastructure. It then received an AES key to decrypt follow-on download code, adapting execution depending on installed security products such as Bitdefender, Kaspersky, V3, Alyac, and Avast.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN mngrdp.site 2023-08-21 2024-02-28
HASH ea986b990b17c7ef847b7abf1b108373 2023-08-21 2023-08-21
URL https://mngrdp.site/hiro/ca.php… 2023-08-21 2023-08-21
URL https://mngrdp.site/hiro/ca.php… 2023-08-21 2023-08-21
URL https://mngrdp.site/hiro/share.… 2023-08-21 2023-08-21
URL https://mngrdp.site/hiro/r.php 2023-08-21 2023-08-21
URL https://mngrdp.site/hiro/re.php 2023-08-21 2023-08-21
URL http://mngrdp.site/hiro/ca.php?… 2023-08-21 2023-08-21
URL http://mngrdp.site/hiro/d.php?n… 2023-08-21 2023-08-21

Related Actors

Related Reports

« Back