AhnLab EDR을 활용한 Kimsuky 그룹의 스피어 피싱 공격 탐지 (AppleSeed, AlphaSeed)

2024-02-08 • Ahnlab • Detection of spear phishing attacks by Kimsuky group using AhnLab EDR (AppleSeed, AlphaSeed) •

https://asec.ahnlab.com/ko/61518/

Thumbnail for AhnLab EDR을 활용한 Kimsuky 그룹의 스피어 피싱 공격 탐지 (AppleSeed, AlphaSeed)

Kimsuky uses spear phishing emails with VBS or JavaScript files disguised as documents to install AppleSeed and, in the observed case, AlphaSeed on targeted systems. The lures vary by target, including government-style documents for diplomacy and defense, business forms for companies, and personal or shopping documents for individuals. The chain creates encrypted payloads under ProgramData, decrypts them with certutil, and runs DLL malware through PowerShell and regsvr32. AppleSeed provides backdoor, downloader, keylogging, screenshot, file collection, and C2 functions, while AlphaSeed is a Go malware family that uses ChromeDP and email-based C2 authentication through cookies.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6a38c84efe52d8e7298d62809ef59a2… 2024-02-08 2025-06-09
DOMAIN peras1.n-e.kr 2024-02-08 2025-06-09
HASH 8302ffe4a9f0282f440d57a79946b29… 2024-02-08 2024-02-08
HASH ec75fa48797a79d752f2ef51bb9fa67… 2024-02-08 2024-02-08
HASH 630c9b5ae35be34202ba57d036e6d68… 2024-02-08 2024-02-08
URL http://peras1.n-e.kr/ 2024-02-08 2024-02-08

Related Actors

Related Reports

« Back