북한 관련 법인을 노리는 CHM 악성코드
2023-03-14 • Secu I • CHM malware targeting North Korea-related organizations •
A spear-phishing campaign targeted South Korean organizations related to North Korea by impersonating a cyber safety bureau email and attaching a ZIP archive containing a malicious CHM help file. Opening the CHM displayed legitimate-looking legal content while embedded script dropped and decoded Document.dat/Document.vbs, added a Run key for persistence, and executed PowerShell to retrieve additional code from attacker infrastructure. The downloaded script created a mutex, captured keystrokes and screenshots, and sent stolen data to C2 paths under ibsq.co.kr, with hashes and URLs supplied as supporting indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ibsq.co.kr | 2023-03-14 | 2023-06-09 |
| HASH | 4f1081d688ba2477e097ebbbf0cce40… | 2023-03-14 | 2023-05-24 |
| HASH | 21c5ed55e9cc5b77e57a42c811f4cbf… | 2023-03-14 | 2023-03-14 |
| HASH | 047c42c77e7ff30fa2e3be8bdf483c0… | 2023-03-14 | 2023-03-14 |
| URL | http://ibsq.co/.kr/config/demo.… | 2023-03-14 | 2023-03-14 |
| URL | http://ibsq.co/.kr/config/show.… | 2023-03-14 | 2023-03-14 |
| URL | http://ibsq.co.kr/config | 2023-03-14 | 2023-03-14 |
| URL | http://libsq.co.kr/config | 2023-03-14 | 2023-03-14 |
| URL | http://libsq.co.kr/config/demo.… | 2023-03-14 | 2023-03-14 |
| DOMAIN | ibsq.co | 2023-03-14 | 2023-03-14 |
| DOMAIN | libsq.co.kr | 2023-03-14 | 2023-03-14 |