疑似Kimsuky(APT-Q-2)针对韩国企业发起攻击

2025-04-11 Qianxin Suspected Kimsuky (APT-Q-2) Attack Against Korean Enterprises

https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247514665&idx=1&sn=37751d5f4cdb6b4d9786010ddd25e751

Thumbnail for 疑似Kimsuky(APT-Q-2)针对韩国企业发起攻击

Qi An Xin reports suspected Kimsuky, tracked internally as APT-Q-2, targeting Korean organizations in sectors including defense, education, energy, government, healthcare, and think tanks. The observed malware set includes a Go dropper, DLL backdoors, and tooling delivered with BlueMoonSoft-signed decoy software, with C2 over dynamic DNS and functions for host and network reconnaissance, payload download, execution, keylogging, clipboard access, and screenshots. A newer backdoor variant checks hostnames against an embedded target list that includes DANAM, suggesting a possible focus on a Korean company tied to electronics, communications, and defense.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://gtfydu.surfnet.ca/index.… 2025-04-11 2026-04-07
DOMAIN gtfydu.surfnet.ca 2025-04-11 2026-04-07
HASH 2a4c2aee3272fad79c70171ffd74537… 2025-04-11 2025-04-11
HASH a4a8dc0f13ddacfad3e0ef8929aac94… 2025-04-11 2025-04-11
HASH 8b978ae1c58af59a426324cc9c5922a… 2025-04-11 2025-04-11
HASH 435e1cb6bcc7c4a4877ee4588157951… 2025-04-11 2025-04-11
HASH 332ef8c184b36f300528d233eb56017… 2025-04-11 2025-04-11
HASH 7b1a82ffb1f9f7cf01b555b63d7963d… 2025-04-11 2025-04-11
URL http://sudifo.ftp.sh/index.php 2025-04-11 2025-04-11
DOMAIN auth.worksmobile.r-e.kr 2025-04-11 2025-04-11
DOMAIN sudifo.ftp.sh 2025-04-11 2025-04-11
DOMAIN auth.linkedin.r-e.kr 2025-04-11 2025-04-11
DOMAIN secure.navdomain.n-e.kr 2025-04-11 2025-04-11
DOMAIN login.hiwork.o-r.kr 2025-04-11 2025-04-11
IPv4 104.37.184.39 2025-04-11 2025-04-11

Related Actors

Related Reports

« Back