鲨鱼的狂欢 — APT-C-55 Kimsuky组织近期BabyShark组件披露

2022-06-07 • Qihoo360 • Shark's Carnival — APT-C-55 Kimsuky organization's recent disclosure of BabyShark components •

https://mp.weixin.qq.com/s/ZV8AOTd7YGUgCTTTZtTktQ

Thumbnail for 鲨鱼的狂欢 — APT-C-55 Kimsuky组织近期BabyShark组件披露

360 attributed multiple first-half 2022 BabyShark component attacks to the Kimsuky organization and linked the malware family to espionage against nuclear security, Korean Peninsula security and cryptocurrency-related targets. The described chain uses malicious DLLs to release VBS scripts, request OneDrive API and 1drv.com URLs, decrypt returned data and upload collected user information to ielsems[.]com for target validation. One related component retrieves desktop.tmp from worldinfocontact[.]club, stores execution logic in a registry value and creates a scheduled task that runs sys.vbs every 29 minutes. The report also identifies an iterative BabyShark DLL sharing export functions and PDB path overlap with earlier Kimsuky BabyShark samples, indicating continued tooling development and infrastructure variation.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ielsems.com 2022-05-05 2024-05-10
HASH 7de6969f867aada10c175e9d4328942e 2022-06-07 2022-06-07
HASH b207265be3bdb32536b3118e0d94660… 2022-06-07 2022-06-07
HASH 8670bff227794e363192395e216ab59… 2022-06-07 2022-06-07
URL https://api.onedrive.com/v1.0/d… 2022-06-07 2022-06-07
URL https://qizzhq.dm.files.1drv.co… 2022-06-07 2022-06-07
URL https://ielsems.com/cic/macro.p… 2022-06-07 2022-06-07
DOMAIN dm.files.1drv.com 2022-06-07 2022-06-07
DOMAIN qizzhq.dm.files.1drv.com 2022-06-07 2022-06-07
DOMAIN 1drv.com 2022-06-07 2022-06-07

Related Actors

Related Reports

« Back