국내 기업 대상 공격에 사용 중인 Xctdoor 악성코드 (Andariel)

2024-06-24 Ahnlab Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

https://asec.ahnlab.com/ko/67034/

Thumbnail for 국내 기업 대상 공격에 사용 중인 Xctdoor 악성코드 (Andariel)

ASEC observed attacks against South Korean defense and manufacturing organizations involving Xctdoor malware and activity assessed as similar to earlier Andariel use of compromised ERP update mechanisms. In the 2024 cases, attackers appear to have abused a domestic ERP update server or vulnerable web servers to deploy XcLoader and Xctdoor, echoing a 2017 Andariel pattern that inserted malicious routines into ClientUpdater.exe to deliver HotCroissant. Xctdoor is described as a Go-based DLL backdoor launched through Regsvr32.exe, copied into an Edge-related local path, persisted with a MicrosoftEdge.lnk shortcut, and injected into processes such as explorer.exe or taskhost variants. Its capabilities include sending host and user information to HTTP C2, executing attacker commands, capturing screenshots, keylogging, logging clipboard data, and collecting drive information, with packet encryption using mt19937 and Base64. The excerpt also notes web-server compromise, probable webshell command execution, and Ngrok logs, making the activity important for tracking DPRK-linked enterprise intrusion and internal propagation tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9bbde4484821335d98b41b44f93276e8 2024-06-24 2024-07-01
HASH c61eca8cf14ce18a54616c3bbe17973… 2024-06-24 2024-07-01
HASH f24627f46ec64cae7a6fa9ee312c43d7 2024-06-24 2024-07-01
HASH 41d5d25de0ca0fdc54c24c484f9f8f55 2024-06-24 2024-07-01
HASH 2e325935b2d1d0a82e63ff2876482956 2024-06-24 2024-07-01
HASH 1417416ba94d9a0f3c34be4c529c244… 2024-06-24 2024-07-01
HASH 3e7715ac57003f8a80119ab348a7a7b… 2024-06-24 2024-07-01
HASH 375f1cc32b6493662a78720c7d905bc3 2024-06-24 2024-07-01
HASH 6928fab25ac1255fbd8d6c1046653919 2024-06-24 2024-07-01
HASH ab8675b4943bc25a51da66565cfc8ac8 2024-06-24 2024-07-01
HASH 934622b6a764a3b4f2a0049c62e66b9… 2024-06-24 2024-07-01
HASH a42ae44761ce3294ce0775fe384d97b6 2024-06-24 2024-07-01
HASH 3d4b90f520ed82ef886f0a38e1a621e… 2024-06-24 2024-07-01
HASH d938201644aac3421df7a3128aa88a53 2024-06-24 2024-07-01
HASH e554b1be8bab11e979c75e2c2453bc6a 2024-06-24 2024-07-01
HASH 54d5be3a4eb0e31c0ba7cb88f0a8e720 2024-06-24 2024-07-01
HASH ad96a8f22faab8b9c361cfccc381cd28 2024-06-24 2024-07-01
HASH 11465d02b0d7231730f3c4202b0400b8 2024-06-24 2024-07-01
HASH 9974b4befa2906a6925e786c4765131… 2024-06-24 2024-07-01
HASH b43a7dcfe53a981831ae763a9a5450fd 2024-06-24 2024-07-01
HASH 4f5e5a392b8a3e0cb32320ed1e8d0604 2024-06-24 2024-07-01
HASH 09a5069c9cc87af39bbb6356af2c1a36 2024-06-24 2024-07-01
URL http://www.jikji.pe.kr/xe/files… 2024-06-24 2024-07-01
URL http://beebeep.info/index.php 2024-06-24 2024-07-01
DOMAIN beebeep.info 2024-06-24 2024-07-01
IPv4 195.50.242.110 2024-06-24 2024-07-01

Related Actors

First seen: Jul 2017
Last seen: Sep 2026

Related Reports

2024-07-19 • 48% Match
#Trend #Andariel #Kimsuky #MoonstoneSleet #Lazarus #T1082 #T1059.003 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1046 #T1112 #T1115 #T1083 #T1497 #T1056.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1071 #T1124 #T1222 #T1552 #T1057 #T1583.003 #T1518.001 #T1547.001 #T1053.005 #T1539 #T1608.005 #T1583.001 #T1059.001 #T1053 #T1552.001 #T1566 #T1059 #T1003 #T1497.001 #T1102.001 #T1574.002 #T1562.001 #T1490 #T1486 #T1129 #T1133 #T1571 #T1548 #T1190 #T1203 #T1564.001 #T1087 #T1562.004 #T1218.011 #T1070.006 #T1547 #T1068 #T1614 #T1573 #T1095 #T1562 #T1070 #T1047 #T1056 #T1176 #T1010 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1202 #T1087.002 #T1021.004 #T1222.001 #T1518 #T1564.003 #T1505.003 #T1069.002 #T1564 #T1595.002 #T1027.005 #T1070.001 #T1056.004 #T1584
Shares tag: Andariel • Published within a month
« Back