疑似Kimsuky(APT-Q-2)针对韩国企业发起攻击
2025-04-11 • Qianxin • Suspected Kimsuky (APT-Q-2) Attack Against Korean Enterprises •
Qi An Xin reports suspected Kimsuky, tracked internally as APT-Q-2, targeting Korean organizations in sectors including defense, education, energy, government, healthcare, and think tanks. The observed malware set includes a Go dropper, DLL backdoors, and tooling delivered with BlueMoonSoft-signed decoy software, with C2 over dynamic DNS and functions for host and network reconnaissance, payload download, execution, keylogging, clipboard access, and screenshots. A newer backdoor variant checks hostnames against an embedded target list that includes DANAM, suggesting a possible focus on a Korean company tied to electronics, communications, and defense.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://gtfydu.surfnet.ca/index.… | 2025-04-11 | 2026-04-07 |
| DOMAIN | gtfydu.surfnet.ca | 2025-04-11 | 2026-04-07 |
| HASH | 2a4c2aee3272fad79c70171ffd74537… | 2025-04-11 | 2025-04-11 |
| HASH | a4a8dc0f13ddacfad3e0ef8929aac94… | 2025-04-11 | 2025-04-11 |
| HASH | 8b978ae1c58af59a426324cc9c5922a… | 2025-04-11 | 2025-04-11 |
| HASH | 435e1cb6bcc7c4a4877ee4588157951… | 2025-04-11 | 2025-04-11 |
| HASH | 332ef8c184b36f300528d233eb56017… | 2025-04-11 | 2025-04-11 |
| HASH | 7b1a82ffb1f9f7cf01b555b63d7963d… | 2025-04-11 | 2025-04-11 |
| URL | http://sudifo.ftp.sh/index.php | 2025-04-11 | 2025-04-11 |
| DOMAIN | auth.worksmobile.r-e.kr | 2025-04-11 | 2025-04-11 |
| DOMAIN | sudifo.ftp.sh | 2025-04-11 | 2025-04-11 |
| DOMAIN | auth.linkedin.r-e.kr | 2025-04-11 | 2025-04-11 |
| DOMAIN | secure.navdomain.n-e.kr | 2025-04-11 | 2025-04-11 |
| DOMAIN | login.hiwork.o-r.kr | 2025-04-11 | 2025-04-11 |
| IPv4 | 104.37.184.39 | 2025-04-11 | 2025-04-11 |