Hermit(隐士)APT组织2020年最新攻击活动分析

2020-04-24 • Tencent • Analysis of the latest attack activities of the Hermit APT organization in 2020 •

https://s.tencent.com/research/report/969

Thumbnail for Hermit(隐士)APT组织2020年最新攻击活动分析

Tencent’s 2020 analysis describes Hermit, a Tencent-named cluster linked through correlation to KONNI/SYSCON/SANNY activity, continuing operations against Korean Peninsula-related NGOs, government bodies, trade companies, and media. The group used malicious Office macro lures tied to COVID-19, the 2020 Tokyo Paralympics, North Korea policy, and North Korean COVID-19 themes, hiding macro behavior by changing font colors and urging users to enable macros. The dropped downloader selected 32- or 64-bit payloads, decrypted CAB packages, used certutil-style download/decryption logic and multiple UAC bypass methods, and installed `wprint.dll` as a service. The RAT used FTP C2, collected system and process information, uploaded encrypted files, and pulled numbered command files for shell execution, file transfer, and payload execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 11750157323eda18b1981399f37765c… 2020-04-24 2020-04-24
HASH 9512f70b55d6feab565d29256f7036e… 2020-04-24 2020-04-24
HASH ba933fe7244fd7d9eeb210e7cf66163… 2020-04-24 2020-04-24
HASH 6f8ffb978fad488756970a5dfe8383d… 2020-04-24 2020-04-24
HASH 9bd4f83442f08fe627d4d7d26d5cf57… 2020-04-24 2020-04-24
HASH 7c9695cf3d5ee9386d8143e33a821dc… 2020-04-24 2020-04-24
HASH 107204043717ef14e2439eb938cd9b1… 2020-04-24 2020-04-24
HASH 1eaea49f4757583554c0db396647c3d… 2020-04-24 2020-04-24
HASH 191ad44dd48305293ecb547c1712fcd… 2020-04-24 2020-04-24
DOMAIN myview-202001.c1.biz 2020-04-24 2020-04-24
DOMAIN win10-ms.c1.biz 2020-04-24 2020-04-24
DOMAIN firefox-plug.c1.biz 2020-04-24 2020-04-24
DOMAIN phpview.mygamesonline.org 2020-04-24 2020-04-24

Related Actors

Related Reports

« Back