Hermit(隐士)APT组织2020年最新攻击活动分析
2020-04-24 • Tencent • Analysis of the latest attack activities of the Hermit APT organization in 2020 •
Tencent’s 2020 analysis describes Hermit, a Tencent-named cluster linked through correlation to KONNI/SYSCON/SANNY activity, continuing operations against Korean Peninsula-related NGOs, government bodies, trade companies, and media. The group used malicious Office macro lures tied to COVID-19, the 2020 Tokyo Paralympics, North Korea policy, and North Korean COVID-19 themes, hiding macro behavior by changing font colors and urging users to enable macros. The dropped downloader selected 32- or 64-bit payloads, decrypted CAB packages, used certutil-style download/decryption logic and multiple UAC bypass methods, and installed `wprint.dll` as a service. The RAT used FTP C2, collected system and process information, uploaded encrypted files, and pulled numbered command files for shell execution, file transfer, and payload execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 11750157323eda18b1981399f37765c… | 2020-04-24 | 2020-04-24 |
| HASH | 9512f70b55d6feab565d29256f7036e… | 2020-04-24 | 2020-04-24 |
| HASH | ba933fe7244fd7d9eeb210e7cf66163… | 2020-04-24 | 2020-04-24 |
| HASH | 6f8ffb978fad488756970a5dfe8383d… | 2020-04-24 | 2020-04-24 |
| HASH | 9bd4f83442f08fe627d4d7d26d5cf57… | 2020-04-24 | 2020-04-24 |
| HASH | 7c9695cf3d5ee9386d8143e33a821dc… | 2020-04-24 | 2020-04-24 |
| HASH | 107204043717ef14e2439eb938cd9b1… | 2020-04-24 | 2020-04-24 |
| HASH | 1eaea49f4757583554c0db396647c3d… | 2020-04-24 | 2020-04-24 |
| HASH | 191ad44dd48305293ecb547c1712fcd… | 2020-04-24 | 2020-04-24 |
| DOMAIN | myview-202001.c1.biz | 2020-04-24 | 2020-04-24 |
| DOMAIN | win10-ms.c1.biz | 2020-04-24 | 2020-04-24 |
| DOMAIN | firefox-plug.c1.biz | 2020-04-24 | 2020-04-24 |
| DOMAIN | phpview.mygamesonline.org | 2020-04-24 | 2020-04-24 |