软件安装包伪装下的Kimsuky(APT-Q-2)窃密行动

2024-01-30 Qianxin Kimsuky (APT-Q-2) secret theft operation disguised as software installation package

https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247509476&idx=1&sn=b0e09436095203b75710836d718d6699&chksm=eb3f7f9b7c2d9f7c2100ae4042ca2b6f455b7861453a14de70bdbb63aa85497ffa8a414a5ebc&scene=132

Thumbnail for 软件安装包伪装下的Kimsuky(APT-Q-2)窃密行动

QiAnXin attributes a January 2024 intrusion set to Kimsuky/APT-Q-2 based on overlap with earlier Kimsuky malware and shared signing, packing, language, and victim-ID patterns. The activity used installers disguised as SGA Solutions products to drop normal setup files while running VMProtect-packed Go malware, including a one-shot stealer identified as TrollAgent and a related backdoor. TrollAgent collects configuration data, SSH and FileZilla directories, Microsoft Sticky Notes, browser data, screenshots, installed-program and system information, then encrypts and exfiltrates the results to C2 URLs such as ar.kostin.p-e.kr and ai.kostin.p-e.kr before deleting itself. The related backdoor persists as svchost.exe via a WindowsUpdate scheduled task and communicates with a compromised Korean domain over randomized POST parameters.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ff3718ae6bd59ad479e375c602a8181… 2024-01-30 2024-07-15
HASH 61b8fbea8c0dfa337eb7ff978124ddf… 2024-01-30 2024-07-15
HASH 2e0ffaab995f22b7684052e53b8c64b… 2024-01-30 2024-07-15
HASH f8ab78e1db3a3cc3793f7680a90dc1d… 2024-01-30 2024-07-15
HASH 955cb4f01eb18f0d259fcb962e36a33… 2024-01-30 2024-07-15
URL http://qi.limsjo.p-e.kr/index.p… 2024-01-30 2024-07-15
URL http://ol.negapa.p-e.kr/index.p… 2024-01-30 2024-07-15
URL http://ai.negapa.p-e.kr/index.p… 2024-01-30 2024-07-15
URL http://ar.kostin.p-e.kr/index.p… 2024-01-30 2024-07-15
DOMAIN ai.negapa.p-e.kr 2024-01-30 2024-07-15
DOMAIN ar.kostin.p-e.kr 2024-01-30 2024-07-15
DOMAIN ol.negapa.p-e.kr 2024-01-30 2024-07-15
DOMAIN qi.limsjo.p-e.kr 2024-01-30 2024-07-15
HASH 6eebb5ed0d0b5553e40a7b1ad739589… 2024-01-30 2024-03-25
HASH a8c24a3e54a4b323973f61630c92eca… 2024-01-30 2024-03-25
DOMAIN ai.kostin.p-e.kr 2024-01-30 2024-03-25
DOMAIN coolsystem.co.kr 2024-01-30 2024-03-25
DOMAIN ai.limsjo.p-e.kr 2024-01-30 2024-03-25
HASH a4b4b5518b377202e4415a064bcfd79… 2024-01-30 2024-03-05
HASH 0dd9aa5b650f519a55c96bf0dee7316… 2024-01-30 2024-03-05
URL http://ai.limsjo.p-e.kr/index.p… 2024-01-30 2024-03-05
URL http://ai.kostin.p-e.kr/index.p… 2024-01-30 2024-03-05
URL http://coolsystem.co.kr/admin/m… 2024-01-30 2024-03-05
HASH 97df5304f53fec6a5d2d2bd75b9310a… 2023-11-21 2024-03-05

Related Actors

Related Reports

« Back