疑似Group123(APT37)针对中韩外贸人士的攻击活动分析

2019-10-28 • Qihoo360 • Analysis of attacks by suspected Group123 (APT37) targeting foreign trade professionals in China and South Korea •

https://mp.weixin.qq.com/s/Wnb-r7SWbGGN-XuQ8fW_jw

Tencent Yujian reports a suspected Group123/APT37 phishing campaign observed from late August to mid-September 2019 against people likely connected to China-South Korea trade. The attack used RAR archive lures with Korean-themed filenames and executables disguised as Word documents, then downloaded a disguised JPG from artmuseums.or.kr that decrypted into a RAT installed as svchost.exe. The RAT collected host information and document lists, including Korean HWP files, while an additional module read C2 data from aconfig.ini and dropped a WinRAR command-line component. Tencent assesses the activity as likely Group123 based on the target profile, Korean-language artifacts, Korea-related compromised C2 infrastructure, and similarities to previously reported ScarCruft/Group123 tradecraft, while noting some overlap with Darkhotel-style behavior.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6f37b758a7a015c2abdab7941b416de… 2019-10-28 2020-03-09
HASH e26c81c569f6407404a726d48aa4d886 2019-10-28 2019-10-28
HASH 8b65bd4c74cd3bbec365ed942a5ccf1… 2019-10-28 2019-10-28
HASH 558ab3602ad6ec843203dd2e28166be… 2019-10-28 2019-10-28
HASH 92f8ed8e41d854ba10f287b8b5198a0… 2019-10-28 2019-10-28
HASH dea0d551900ce032e8684282977bbe5… 2019-10-28 2019-10-28
HASH 9f8859decf87da412a386141364462f… 2019-10-28 2019-10-28
URL http://casaabadia.es/ 2019-10-28 2019-10-28
URL http://artmuseums.or.kr/swfuplo… 2019-10-28 2019-10-28
URL http://fjtlephare.fr/wp-content… 2019-10-28 2019-10-28
DOMAIN artmuseums.or.kr 2019-10-28 2019-10-28
DOMAIN fjtlephare.fr 2019-10-28 2019-10-28
DOMAIN casaabadia.es 2019-10-28 2019-10-28

Related Actors

Related Reports

« Back