북한 관련 법인을 노리는 CHM 악성코드

2023-03-14 • Secu I • CHM malware targeting North Korea-related organizations •

https://stic.secui.com/main/main/threatInfo?id=119

A spear-phishing campaign targeted South Korean organizations related to North Korea by impersonating a cyber safety bureau email and attaching a ZIP archive containing a malicious CHM help file. Opening the CHM displayed legitimate-looking legal content while embedded script dropped and decoded Document.dat/Document.vbs, added a Run key for persistence, and executed PowerShell to retrieve additional code from attacker infrastructure. The downloaded script created a mutex, captured keystrokes and screenshots, and sent stolen data to C2 paths under ibsq.co.kr, with hashes and URLs supplied as supporting indicators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ibsq.co.kr 2023-03-14 2023-06-09
HASH 4f1081d688ba2477e097ebbbf0cce40… 2023-03-14 2023-05-24
HASH 21c5ed55e9cc5b77e57a42c811f4cbf… 2023-03-14 2023-03-14
HASH 047c42c77e7ff30fa2e3be8bdf483c0… 2023-03-14 2023-03-14
URL http://ibsq.co/.kr/config/demo.… 2023-03-14 2023-03-14
URL http://ibsq.co/.kr/config/show.… 2023-03-14 2023-03-14
URL http://ibsq.co.kr/config 2023-03-14 2023-03-14
URL http://libsq.co.kr/config 2023-03-14 2023-03-14
URL http://libsq.co.kr/config/demo.… 2023-03-14 2023-03-14
DOMAIN ibsq.co 2023-03-14 2023-03-14
DOMAIN libsq.co.kr 2023-03-14 2023-03-14

Related Actors

Related Reports

« Back