킴수키(Kimsuky)조직의 'Mail Online Security' 프로그램 위장 공격 주의!

2023-06-26 • ESTSecurity • Beware of spoofing attacks from the Kimsuky organization's 'Mail Online Security' program! •

https://blog.alyac.co.kr/5185

Thumbnail for 킴수키(Kimsuky)조직의 'Mail Online Security' 프로그램 위장 공격 주의!

ESTsecurity’s ESRC reports a Kimsuky campaign distributing malware disguised as a legitimate “Mail Online Security” installer, assessed as a variant of activity previously warned about by South Korea’s NCSC/KISA. The lure used an ISO containing setup.exe with security-program branding; execution displayed a fake installer while unrar.exe unpacked password-protected plugin DLLs in the background. The DLL chain injected a payload into Chrome, copied Chrome into ProgramData, placed a malicious version.dll for DLL hijacking, registered “Chrome Updater” for autorun, and ultimately ran a command-and-control component. ESRC linked the activity to Kimsuky’s Blue Estimate campaign and noted capabilities including self-deletion, file upload/download, and process PID/name reporting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ea109b198709fb6967c1613071caed8… 2023-06-26 2023-08-16
HASH 5841f734f0dbc3acdc6cc7f0c9a4c53… 2023-06-26 2023-08-16
HASH 73ed08cc7bd0733a232124d6829a379… 2023-06-26 2023-08-16
HASH a05397d3e7c66ef89a1e60c84cbf689… 2023-06-26 2023-08-16
HASH 05e65d27a462ed41baa8765e82a2a00… 2023-06-26 2023-08-16

Related Actors

Related Reports

« Back