국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)

2024-03-19 • Ahnlab • Malicious code disguised as installation files of domestic public institutions (Kimsuky group) •

https://asec.ahnlab.com/ko/62117/

Thumbnail for 국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)

AhnLab reports that Kimsuky distributed a dropper disguised as a Korean public institution installer, signed with a valid domestic certificate, to deploy the Endoor backdoor. The dropper creates src.rar and unrar.exe, extracts the payload with the password 1q2w3e4r, and runs Endoor with an install argument so it copies itself to %USERPROFILE%\svchost.exe and registers a Windows Backup scheduled task. Follow-on activity included suspected Endoor updates, Mimikatz execution with sekurlsa::logonpasswords, screenshot theft, and use of Endoor and Nikidoor infrastructure including ngrok-free[.]app and minish.wiki[.]gd. The report links the activity to Kimsuky's continued use of signed malware, backdoors, and credential theft against Korean targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7bd723b5e4f7b3c645ac04e763dfc91… 2024-03-19 2024-12-13
HASH b873c82dd91fba08d60d05219accd91… 2024-03-19 2024-03-26
HASH f03618281092b02589bca833f674e8a0 2024-03-19 2024-03-26
HASH 0a492d89ea2c05b1724a58dd05b7c47… 2024-03-19 2024-03-26
HASH 18bb14af8d70a46e544a87b52edfefe… 2024-03-19 2024-03-26
URL http://minish.wiki.gd/index.php 2024-03-19 2024-03-26
URL http://minish.wiki.gd/eng.db 2024-03-19 2024-03-26
URL http://minish.wiki.gd/upload.php 2024-03-19 2024-03-26
URL https://real-joey-nicely.ngrok-… 2024-03-19 2024-03-26
URL http://minish.wiki.gd/c.pdf 2024-03-19 2024-03-26
URL https://fitting-discrete-lemur.… 2024-03-19 2024-03-26
DOMAIN minish.wiki.gd 2024-03-19 2024-03-26
IPv4 210.16.120.210 2024-03-19 2024-03-26

Related Actors

Related Reports

« Back