킴수키(Kimsuky)조직의 'Mail Online Security' 프로그램 위장 공격 주의!
2023-06-26 • ESTSecurity • Beware of spoofing attacks from the Kimsuky organization's 'Mail Online Security' program! •
ESTsecurity’s ESRC reports a Kimsuky campaign distributing malware disguised as a legitimate “Mail Online Security” installer, assessed as a variant of activity previously warned about by South Korea’s NCSC/KISA. The lure used an ISO containing setup.exe with security-program branding; execution displayed a fake installer while unrar.exe unpacked password-protected plugin DLLs in the background. The DLL chain injected a payload into Chrome, copied Chrome into ProgramData, placed a malicious version.dll for DLL hijacking, registered “Chrome Updater” for autorun, and ultimately ran a command-and-control component. ESRC linked the activity to Kimsuky’s Blue Estimate campaign and noted capabilities including self-deletion, file upload/download, and process PID/name reporting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ea109b198709fb6967c1613071caed8… | 2023-06-26 | 2023-08-16 |
| HASH | 5841f734f0dbc3acdc6cc7f0c9a4c53… | 2023-06-26 | 2023-08-16 |
| HASH | 73ed08cc7bd0733a232124d6829a379… | 2023-06-26 | 2023-08-16 |
| HASH | a05397d3e7c66ef89a1e60c84cbf689… | 2023-06-26 | 2023-08-16 |
| HASH | 05e65d27a462ed41baa8765e82a2a00… | 2023-06-26 | 2023-08-16 |