CJ Olivenetworks 인증서 악용 악성코드 분석 : 유출된 인증서를 악용한 Kimsuky 그룹의 피싱 캠페인

2025-05-30 Igloo Cyber threat report on Kimsuky, CJOliveNetworks

https://www.igloopedia.com/1f5f216a-760c-80c0-a6e3-e07e401caf23

Thumbnail for CJ Olivenetworks 인증서 악용 악성코드 분석 : 유출된 인증서를 악용한 Kimsuky 그룹의 피싱 캠페인

IGLOO links a CJ Olivenetworks certificate-abuse malware sample to Kimsuky based on tradecraft overlap with an earlier Nexaweb certificate-abuse phishing campaign, including a Go-built dropper, Acrobat-like icon, and a backdoor internally named httpSpy.dll. The dropper appears to have been delivered in a spear-phishing RAR and used a screen-saver executable disguised as a document, creating a decoy PDF tied to a Korea Institute of Machinery and Materials IP access request. After execution, it deletes itself, drops an unsigned DLL as config.dat under the public user directory, and runs its exported function with rundll32.exe. The backdoor uses VMProtect-like obfuscation, decrypts strings and APIs dynamically, establishes persistence via registry or service mechanisms, stores configuration with NTFS alternate data streams, and attempts HTTP C2 communication with gsegse.dasfesfgsegsefsede.o-r.kr. The abuse of a timestamped leaked certificate matters because it can preserve apparent signature validity even after revocation, increasing trust from users and security controls.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://gsegse.dasfesfgsegsefsed… 2025-05-19 2026-04-07
DOMAIN gsegse.dasfesfgsegsefsede.o-r.kr 2025-05-15 2026-04-07
HASH 3314b6ea393e180c20db52448ab6980… 2024-06-07 2025-06-09
HASH dcb571286147ffc084f35aa9e467144… 2025-05-30 2025-05-30
HASH 17fbf6c228c30182818562f989e6290… 2025-05-30 2025-05-30
URL http://gsegse.dasfesfgsegsefsed… 2025-05-30 2025-05-30
HASH 123aefe0734da130b475bfdad6c3ebe… 2025-05-15 2025-05-30
HASH 7047efbd15b20086933a3e41f23252d… 2025-05-15 2025-05-30
HASH 000e2926f6e094d01c64ff972e958cd… 2024-06-19 2025-05-30

Related Actors

Related Reports

« Back