APT-C-55
2021-11-19 • Qihoo360 • 疑似Kimsuky针对韩国军工行业的攻击
APT-C-55 is the designation Chinese security firm Qihoo 360 uses for the Kimsuky threat group (also tracked under aliases including Mystery Baby, Baby Coin, Smoke Screen, and Black Banshee), a suspected East Asian state-linked espionage actor. Qihoo 360's threat research team has tracked the group since at least November 2021, when it caught a sample abusing a modified commercial browser password-recovery tool to test credential-collection functionality, injected into svchost.exe after RC4/ZLIB-decrypted staging. The group primarily targets South Korean government, defense-industrial, media, and academic/education organizations, relying on spear-phishing with topical lure documents, including HWP/Hancom-themed loaders, to build trust before harvesting sensitive information. Qihoo 360 has also documented the group's use of the BabyShark malware component, first seen in February 2019 targeting United States national-security think tanks and academic institutions, later repurposed for espionage on nuclear-security and Korean-peninsula issues as well as financially motivated cryptocurrency-related intrusions; BabyShark uses OneDrive-hosted staging URLs and VBScript decryption chains. Qihoo 360 notes infrastructure overlap with the Konni activity cluster.
-
43
Related Actors
-
799
Related Reports