It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp

2022-09-14 • Mandiant •

https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing

Thumbnail for It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp

Mandiant identified UNC4034 using a fake Amazon job opportunity to move a media-industry victim from email to WhatsApp and deliver a malicious ISO named amazon_assessment.iso. The ISO contained a trojanized PuTTY executable and a Readme with connection details; attempting the SSH workflow triggered embedded malicious code that dropped colorui.dll and used DLL search order hijacking through colorcpl.exe. Persistence was created with a scheduled task named PackageColor, and the DLL decrypted DAVESHELL shellcode that loaded AIRDRY.V2, a VMProtect-packed evolution of the AIRDRY/BLINDINGCAN backdoor. Mandiant noted overlaps suggesting a North Korea nexus, and the case is significant because it combines recruiter-themed social engineering, ISO delivery, trojanized legitimate tooling, and a plugin-oriented backdoor chain.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://turnscor.com/wp-include… 2022-09-14 2023-09-29
URL https://hurricanepub.com/includ… 2022-09-14 2023-09-29
DOMAIN hurricanepub.com 2022-09-14 2023-09-29
DOMAIN turnscor.com 2020-12-15 2023-09-29
HASH 8cc60b628bded497b11dbc04facc7b5… 2022-09-14 2022-11-03
HASH e03da0530a961a784fbba93154e9258… 2022-09-14 2022-11-03
HASH cf22964951352c62d553b228cf4d2d9… 2022-09-14 2022-11-03
IPv4 137.184.15.189 2022-09-14 2022-11-03
HASH aaad412aeb0f98c2c27bb817682f086… 2022-09-14 2022-09-29
HASH 1492fa04475b89484b5b0a02e6ba3e5… 2022-09-14 2022-09-29
HASH 6d1a88fefd03f20d4180414e199eb23a 2022-09-14 2022-09-14
HASH 3ac82652cf969a890345db1862deff4… 2022-09-14 2022-09-14
URL https://www.elite4print.com/sup… 2022-09-14 2022-09-14

Related Actors

Related Reports

« Back