UNC4034
2022-09-14 • Mandiant • It's Time to PuTTY! DPRK Job Opportunity Phishing…
Mandiant Managed Defense identified the threat cluster it tracks as UNC4034 during proactive threat hunting in July 2022, assessing several overlaps with other activity suspected to have a North Korea nexus. UNC4034 established contact with a media-industry employee by offering a fake Amazon job opportunity, then moved communication to WhatsApp, where it shared a malicious ISO disk image disguised as an assessment file. The ISO contained a trojanized, unsigned build of the open-source PuTTY utility that, once the victim attempted an SSH connection, wrote a legitimate Windows executable and a companion malicious DLL to disk, using DLL search-order hijacking and scheduled-task persistence to deploy the AIRDRY.V2 backdoor, an evolution of malware Mandiant had previously tracked, also known publicly as BLINDINGCAN. Mandiant found a near-identical second ISO on VirusTotal using a different code-insertion location but the same payload-dropping mechanism and backdoor, indicating a repeatable operational toolkit rather than a one-off intrusion.
-
60
Related Actors
-
690
Related Reports