Hermit

2018-12-20 • TencentHermit(隐士)APT组织2020年最新攻击活动分析

Tencent's threat intelligence center named this actor Hermit in December 2018 after identifying a new intrusion set whose loading mechanism and download infrastructure closely resembled a previously exposed FTP-based remote-access trojan the company had already linked to the Konni cluster and suspected of ties to Darkhotel activity. The name refers to the group's decoy documents, whose malicious lure content stayed hidden until a victim enabled macros. Tencent traced the activity to at least April 2018 and found it continuing into 2020, with primary targets being political figures, government departments, non-governmental organizations, trade companies, and media connected to the Korean peninsula. Its consistent method is spear-phishing email carrying Office documents with malicious macros; once enabled, the macro fetches and decodes a downloader that retrieves an architecture-specific package installing a backdoor capable of file transfer, process management, and remote command execution, at times paired with a hidden-interface remote-control tool. By 2020 the group had refined its user-account-control bypass techniques and continued using topical lures, including pandemic and Korean-policy themes, while exfiltrating encrypted victim data over file-transfer-protocol infrastructure.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster