疑似Kimsuky针对韩国军工行业的攻击

2021-07-08 • Qihoo360 • Suspected Kimsuky attacks targeting South Korea's military industry •

https://mp.weixin.qq.com/s/y4TGzrhr2rvVk5EAca91hA

Thumbnail for 疑似Kimsuky针对韩国军工行业的攻击

360 reports a suspected Kimsuky operation aimed at South Korean military or defense-related targets, using a PE sample disguised with a Microsoft-style icon and a Korean HWP procurement-plan lure. The first-stage malware displayed the decoy document, created a version-like mutex, invoked mshta.exe against vpn.atooi.ga, and then self-deleted with a BAT script. Related DLL samples used similar mutex naming, decrypted embedded shellcode, and injected it into rundll32.exe, where the shellcode attempted to contact 27.102.127.240 for additional code. The analysis links the backdoor's string/API decryption approach to historical Kimsuky tooling while retaining cautious attribution as suspected Kimsuky activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8828848abd439698aed441197e455be… 2021-07-08 2021-07-08
HASH 12c9f6699f64c757aebf5d9120d95a6… 2021-07-08 2021-07-08
URL http://vpn.atooi.ga/?query=5 2021-07-08 2021-07-08
DOMAIN vpn.atooi.ga 2021-07-08 2021-07-08
IPv4 27.102.127.240 2021-07-08 2021-07-08

Related Actors

Related Reports

« Back