APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析

2026-09-10 Qihoo360 Analysis of APT-C-55 (Kimsuky) Attack Chain Using a Disguised Installer to Deploy a Remote Access Trojan

https://mp.weixin.qq.com/s/9ilhH-WUqeNCStDfbrBsrw

Thumbnail for APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析

Qihoo 360 attributes a multi-stage infection chain to Kimsuky (APT-C-55), beginning with a trojanized OrionQuests installer that drops a malicious LNK file. The LNK decrypts PowerShell that checks for analysis tools and virtual machines, profiles the host, and retrieves a disguised second-stage .NET payload. Persistence relies on a scheduled task masquerading as a Google Chrome update. The modular backdoor connects to 107.172.249.140 over TCP port 443 and supports encrypted delivery of additional plugins.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://38.180.204.13/unicorn/un… 2026-09-10 2026-09-10
URL http://38.180.204.13/unicorn/mo… 2026-09-10 2026-09-10
URL http://217.60.36.94/unicorn/mor… 2026-09-10 2026-09-10
IPv4 217.60.36.94 2026-09-10 2026-09-10
URL http://217.60.36.94/unicorn/uni… 2026-09-10 2026-09-10
HASH 9ae48e0ce0dfcac0245237fa220dd52d 2026-09-10 2026-09-10
HASH 7479bedf5813a1527199f8958e898d19 2026-09-10 2026-09-10
HASH 3c64c75c9e6a3da7fbc766deb2081219 2026-09-10 2026-09-10
HASH 04272144d33668f99f7cf2255289e351 2026-09-10 2026-09-10
IPv4 38.180.204.13 2026-07-21 2026-09-10
IPv4 107.172.249.140 2026-07-21 2026-09-10

Related Actors

Related Reports

« Back