Kimsuky APT组织使用新型的AppleSeed Android组件伪装成安全软件对韩特定目标进行攻击

2021-05-06 • Qihoo360 • The Kimsuky APT organization uses the new AppleSeed Android component to disguise itself as security software to attack specific targets in South Korea. •

https://mp.weixin.qq.com/s/8RgFvA_rOR2nIGxjWbEq-w

Thumbnail for Kimsuky APT组织使用新型的AppleSeed Android组件伪装成安全软件对韩特定目标进行攻击

The source describes Kimsuky activity using a new Android component associated with AppleSeed/AutoUpdate and disguised as a KISA mobile security-check application to target selected South Korean victims. The APK collected Android device information, contacted download.riseknite.life with m=a, m=c, and m=d parameters, enumerated files under /sdcard, uploaded disguised and encrypted archives, executed commands, read SMS messages, and could send SMS or clear app data. The report also correlates the Android backdoor with Kimsuky Windows droppers and AppleSeed DLL infrastructure, including onedrive-upload.ikpoo.cf, based on similar traffic parameters and decryption logic. The activity illustrates Kimsuky’s continued expansion across Windows and Android payloads against South Korea-focused targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fa4d05e42778581d931f07bb213389f… 2021-05-06 2021-08-23
HASH 2365a48f7d6cf6dcc83195f06ea11b9… 2021-05-06 2021-05-06
URL http://download.riseknite.life/… 2021-05-06 2021-05-06
DOMAIN download.riseknite.life 2021-05-06 2021-05-06
HASH 2b0565b5117895e296e67e480953c90… 2021-05-06 2021-05-06
HASH 3df07235793c8b7c850c173c4b29e97… 2021-05-06 2021-05-06
HASH f8e972a26117bd14f5ec4dca9de0244… 2021-05-06 2021-05-06

Related Actors

Related Reports

« Back