다양한 원격 제어 도구들을 악용하는 공격자들

2022-10-11 • Ahnlab • Attackers exploiting various remote control tools •

https://asec.ahnlab.com/ko/39761/

Thumbnail for 다양한 원격 제어 도구들을 악용하는 공격자들

AhnLab reviews how attackers abuse legitimate remote administration tools and malicious RATs to take control of infected systems. The report distinguishes backdoors, remote shells, Remote Access Trojans, and normal tools such as AnyDesk and TeamViewer that can be misused after intrusion. It notes that remote-control capability is often an intermediate stage in larger enterprise attacks, enabling lateral movement, information theft, and later ransomware deployment. Examples include commercial or leaked RAT families such as Remcos, AveMaria, BitRAT, RedLine, and NanoCore, alongside legitimate administration software used to blend into victim environments.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d2fff992e40ce18ff81b9a92fa1cb93… 2022-10-11 2022-10-11
HASH e26721913bb394b372d939696633096… 2022-10-11 2022-10-11
URL http://bbq.zzhreceive.top/tmate 2022-10-11 2022-10-11
DOMAIN bbq.zzhreceive.top 2022-10-11 2022-10-11
IPv4 58.180.56.28 2022-10-11 2022-10-11
IPv4 106.250.168.50 2022-10-11 2022-10-11
IPv4 119.201.213.146 2022-10-11 2022-10-11
IPv4 183.111.148.147 2022-10-11 2022-10-11

Related Reports

« Back