Kimsuky APT组织对韩国国防安全相关部门的定向攻击活动分析

2021-06-23 • Qihoo360 • Analysis of Kimsuky APT's targeted attack activities on South Korean defense and security-related departments •

https://www.freebuf.com/articles/paper/278762.html

Thumbnail for Kimsuky APT组织对韩国国防安全相关部门的定向攻击活动分析

ThreatBook described Kimsuky activity targeting South Korean defense and security-related organizations over roughly six months with lures themed around the U.S.-South Korea summit, Ministry of National Defense bidding documents, and a fake KISA mobile security app. The Windows infection chains disguised malware as HWP documents or Microsoft-style components, used mshta.exe to retrieve remote scripts from infrastructure such as mail.kumb.cf and v*p*n.atooi.ga, and deployed espionage RAT components with persistence, remote shell, file transfer, keylogging, screen capture, file monitoring, and USB monitoring functions. The Android variant masqueraded as “KISA Mobile Security,” requested sensitive permissions, contacted app.at-me.ml, and collected SMS and file information. The report also linked several domains to 104.128.239.70 and noted Korean reporting that Kimsuky abused VPN access in the KAERI intrusion, while treating any Lazarus coordination as a suspected overlap rather than a confirmed attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fe1a734019f0dc714bd3360e2369853… 2021-06-03 2021-09-12
DOMAIN app.at-me.ml 2021-06-03 2021-09-12
IPv4 104.128.239.70 2021-06-03 2021-09-12
HASH 97e2f035a2fac5ee8d07a204fcf36ed… 2021-06-23 2021-06-23
HASH 679a17688cde5d57c4662df12ab134f… 2021-06-23 2021-06-23
HASH fd59597169668b90c47d0ad6db1bcd7… 2021-06-23 2021-06-23
HASH 6184acd90c735783aafd32c3346c943… 2021-06-23 2021-06-23
URL http://app.at-me.ml/index.php?m… 2021-06-23 2021-06-23
URL http://mail.kumb.cf/?query=5 2021-06-23 2021-06-23
DOMAIN mail.kumb.cf 2021-06-23 2021-06-23
URL http://app.at-me.ml/index.php 2021-06-03 2021-06-23
HASH 742e04ae5f2cd42cf514abbd1956c59… 2021-02-03 2021-06-23

Related Actors

Related Reports

« Back