APT-C-55(Kimsuky)组织假借“生日祝福”为诱饵分发Quasar RAT的攻击活动分析

2023-06-05 • Qihoo360 • Analysis of the attack activities of the APT-C-55 (Kimsuky) organization distributing Quasar RAT under the guise of "birthday greetings" as bait •

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247492682&idx=1&sn=a8d1e06b180d93021da9023d773941da&chksm=f9c1d743ceb65e558f03c369efc336ae837f0cea080ec40d5bf96b7a092260a21ebb7c4f159a&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-55(Kimsuky)组织假借“生日祝福”为诱饵分发Quasar RAT的攻击活动分析

360 attributes with medium confidence an APT-C-55/Kimsuky campaign that used Korean-language artifacts and a birthday-greeting CHM lure to target South Korea. Execution of the CHM loaded remote VBS and PowerShell stages, created a WindowsAppCertification directory under ProgramData, established a scheduled task, and downloaded additional payloads from Google Drive URLs. The loader, identified internally as ProcessHollowingCsharp, RC4-decrypted Quasar RAT v1.3.0.0 and injected it into CasPol.exe, matching previously reported Kimsuky QuasarRAT activity and related malicious document tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9e42c9b206789a24fdf3655af190d16… 2023-06-05 2023-06-05
HASH 514cd71508ca9b3f35afe09a943e97c… 2023-06-05 2023-06-05
HASH c26e3c33d2f3a5a13282eee6e764bd79 2023-06-05 2023-06-05
HASH f4b463ff459690d5d4750c059248234… 2023-06-05 2023-06-05
HASH 91bec0462dd90503174c27d28dd7367… 2023-06-05 2023-06-05
HASH f667bf120d5760845fcdd2f02254eff4 2023-06-05 2023-06-05
HASH 86a2cf6525c30c9d39cd6a4b0f67670b 2023-06-05 2023-06-05
HASH 9ff5e42ff3f6f63eac1608b1a63ab76… 2023-06-05 2023-06-05
HASH a9106a7c36418b9e4a19d0c7cc654e46 2023-06-05 2023-06-05
HASH 29652a5599aab8088d8bfd453471fefd 2023-06-05 2023-06-05
HASH eeac6740c0730a6950b540c18231ed6… 2023-06-05 2023-06-05
HASH 5dd86a895d7d4d70dbb29887604941b… 2023-05-24 2023-06-05

Related Actors

Related Reports

« Back