APT Attacks Using Cloud Storage

2024-06-11 Ahnlab

https://asec.ahnlab.com/en/66429/

Thumbnail for APT Attacks Using Cloud Storage

The threat actor appears to set the attack targets in advance and distribute malware after continuously collecting relevant information. The malware that is launched through the above process is XenoRAT which can perform various malicious behaviors such as loading malware, launching and terminating processes, and communicating with the C2 server based on the threat actor’s commands. Given that the threat actor also uses files disguised as documents such as money deposit contracts, insurance, and loans that include the personal information of specific individuals, it appears that they distribute malware to specific designated targets. [1][2][3] The threat actors mainly upload malicious scripts, RAT malware strains, and decoy documents onto the cloud servers to perform attacks.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 159.100.29.122 2024-05-23 2024-08-21
HASH ebbc383057b473eeb958a897d85f283… 2024-05-23 2024-06-11
HASH 386a4b5f0d0d4e307869291a5e9d0b6… 2024-05-23 2024-06-11
HASH 4ed61dac39786c11ec4aea0cf29a5f6… 2024-05-23 2024-06-11
HASH f3dc19d761e940762c142cb0eb308bd… 2024-05-23 2024-06-11
HASH 2d1b749753e9c77be967a469f932391… 2024-05-23 2024-06-11
HASH 55c0f2181123215e927225228c886b2… 2024-05-23 2024-06-11
HASH a23b3e72adfc7dc4fa275135fc85be9… 2024-05-23 2024-06-11
HASH 8c40e573bd36615e03412a8fa794cf6… 2024-05-23 2024-06-11
HASH 66a4a00c3897b0c095bee223efb44e6… 2024-05-23 2024-06-11
HASH 238cd8f609b06258ab8b4ded82ebbff8 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11
EMAIL [email protected] 2024-05-23 2024-06-11

Related Reports

« Back