疑似Kimsuky(APT-Q-2)以军工招聘为饵攻击欧洲

2024-06-20 Qianxin Suspected Kimsuky (APT-Q-2) Uses Military Recruitment Lures Against Europe

https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247510817&idx=1&sn=733782ef0505c107304c149a763c1ce2

Thumbnail for 疑似Kimsuky(APT-Q-2)以军工招聘为饵攻击欧洲

QiAnXin reports a suspected Kimsuky, or APT-Q-2, campaign using fake General Dynamics and Lockheed Martin recruitment lures for defense jobs in Germany to target European military industry personnel. The activity used JSE, C++ and Go droppers to place a DLL payload under ProgramData or fetch it from attacker infrastructure, then execute it with regsvr32. The malware persisted through a CacheDB service when elevated or an HKCU Run key otherwise, stored configuration in NTFS alternate data streams or decrypted it from the .data section, and used RC4 encrypted HTTP POST C2 traffic. QiAnXin cites code similarity, Korean language artifacts, the username niki, and related r-e.kr and o-r.kr infrastructure as reasons the activity is likely connected to Kimsuky, while noting the fake recruitment theme also resembles Lazarus tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 24a42a912c6ad98ab3910cb1e031edb… 2024-06-07 2025-06-09
HASH 3314b6ea393e180c20db52448ab6980… 2024-06-07 2025-06-09
DOMAIN download.uberlingen.com 2024-06-07 2025-06-09
HASH 000e2926f6e094d01c64ff972e958cd… 2024-06-19 2025-05-30
HASH cca1705d7a85fe45dce9faec5790d49… 2024-06-19 2025-05-24
DOMAIN online.viewers.r-e.kr 2024-06-07 2024-08-24
DOMAIN share.dihl-defence.o-r.kr 2024-06-07 2024-08-24
HASH f5ceddb00158dd6ffee753a40bf7f85… 2024-06-20 2024-06-20
HASH cc75fad4c455d8a969334ba8df56fff… 2024-06-20 2024-06-20
URL http://download-attachments.moo… 2024-06-20 2024-06-20
URL http://apphelloworld.crabdance.… 2024-06-20 2024-06-20
DOMAIN paypal.uberlingen.com 2024-06-20 2024-06-20
DOMAIN apphelloworld.crabdance.com 2024-06-20 2024-06-20
HASH 5b3cc9cced1ef0cb0bba5549cc2ac09… 2024-06-19 2024-06-20
HASH a637d9836285254831c80fdd407f4da… 2024-06-19 2024-06-20
URL http://imagedownload.ignorelist… 2024-06-19 2024-06-20
URL http://en.uberlingen.com/index.… 2024-06-19 2024-06-20
URL http://playboys.chickenkiller.c… 2024-06-19 2024-06-20
DOMAIN imagedownload.ignorelist.com 2024-06-19 2024-06-20
DOMAIN download-attachments.mooo.com 2024-06-19 2024-06-20
DOMAIN en.uberlingen.com 2024-06-19 2024-06-20
DOMAIN playboys.chickenkiller.com 2024-06-19 2024-06-20
IPv4 67.217.62.219 2024-06-19 2024-06-20
URL http://download.uberlingen.com/… 2024-06-07 2024-06-20
DOMAIN share-defence.uberlingen.com 2024-06-07 2024-06-20
IPv4 94.131.120.80 2024-06-07 2024-06-20

Related Actors

Related Reports

« Back