APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析
2026-09-10 • Qihoo360 • Analysis of APT-C-55 (Kimsuky) Attack Chain Using a Disguised Installer to Deploy a Remote Access Trojan •
Qihoo 360 attributes a multi-stage infection chain to Kimsuky (APT-C-55), beginning with a trojanized OrionQuests installer that drops a malicious LNK file. The LNK decrypts PowerShell that checks for analysis tools and virtual machines, profiles the host, and retrieves a disguised second-stage .NET payload. Persistence relies on a scheduled task masquerading as a Google Chrome update. The modular backdoor connects to 107.172.249.140 over TCP port 443 and supports encrypted delivery of additional plugins.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://38.180.204.13/unicorn/un… | 2026-09-10 | 2026-09-10 |
| URL | http://38.180.204.13/unicorn/mo… | 2026-09-10 | 2026-09-10 |
| URL | http://217.60.36.94/unicorn/mor… | 2026-09-10 | 2026-09-10 |
| IPv4 | 217.60.36.94 | 2026-09-10 | 2026-09-10 |
| URL | http://217.60.36.94/unicorn/uni… | 2026-09-10 | 2026-09-10 |
| HASH | 9ae48e0ce0dfcac0245237fa220dd52d | 2026-09-10 | 2026-09-10 |
| HASH | 7479bedf5813a1527199f8958e898d19 | 2026-09-10 | 2026-09-10 |
| HASH | 3c64c75c9e6a3da7fbc766deb2081219 | 2026-09-10 | 2026-09-10 |
| HASH | 04272144d33668f99f7cf2255289e351 | 2026-09-10 | 2026-09-10 |
| IPv4 | 38.180.204.13 | 2026-07-21 | 2026-09-10 |
| IPv4 | 107.172.249.140 | 2026-07-21 | 2026-09-10 |
Related Actors
Related Reports
Shares tags: APT-C-55, LNK • Same author: Qihoo360
Shares tags: APT-C-55, LNK • Same author: Qihoo360
Shares tags: APT-C-55, LNK • Same author: Qihoo360
2026-09-09 •
46% Match
#Kimsuky
#LNK
#GitHub
#LOTL
#T1082
#T1567.002
#T1140
#T1083
#T1204.002
#T1057
#T1053.005
#T1105
#T1016
#T1087.001
Shares tags: LNK, LOTL • Published within a week
Shares tag: APT-C-55 • Same author: Qihoo360
Shares tag: APT-C-55 • Same author: Qihoo360