'한독 합동 사이버 보안 권고' 관련 안랩 대응 현황

2023-03-20 • Ahnlab • Status of AhnLab's response to the ‘Korea-German Joint Cybersecurity Recommendation' •

https://asec.ahnlab.com/ko/49964/

Thumbnail for '한독 합동 사이버 보안 권고' 관련 안랩 대응 현황

AhnLab summarized its detections for IOCs published in the South Korea–Germany joint advisory on Kimsuky. The advisory said Kimsuky used Chromium browser extensions and Android app-developer support functions to steal account information, primarily targeting Korean Peninsula and North Korea specialists while warning that the techniques could scale beyond that audience. AhnLab mapped the released MD5 indicators to detections including Backdoor/JS.Agent for JavaScript extension components and Android-Trojan/Kimsuky or Android-Trojan/FastSpy for mobile samples. The source is an IOC-response note rather than a full intrusion narrative, so the operational value is the vendor detection mapping for the joint advisory artifacts.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 11b99f460bf14c902083d2c9559da6f… 2023-03-20 2023-05-16
HASH a4daa30a2ef6943d8eec7759246f658… 2023-03-20 2023-05-16
HASH fdd0e18e841d3ec4e501dd8bf0da682… 2022-10-25 2023-04-19
HASH 539231dea156e29bd6f7ed8430bd08a… 2022-10-25 2023-04-19
HASH 031bde16d3b75083b0adda754aa982d… 2022-10-25 2023-04-19
HASH 51527624e7921a8157f820eb0ca78e29 2023-03-20 2023-03-20

Related Actors

Related Reports

« Back