Kimsuky Threat Group Uses RDP to Control Infected Systems

2023-10-17 • Ahnlab •

https://asec.ahnlab.com/en/57873/

Thumbnail for Kimsuky Threat Group Uses RDP to Control Infected Systems

AhnLab details Kimsuky activity in which presumed spear phishing led to BabyShark installation and later deployment of RDP-control tooling on compromised Windows systems. The group used scripts and loaders such as hwp.bat, k.ps1, OneNote.vbs, pow.ps1, and desktop.r7u to collect information, log keystrokes, decrypt payloads, and inject code into legitimate processes. Additional payloads included multiple.exe, which changes termsrv.dll, enables multiple RDP sessions, and creates a hidden IIS_USER administrator account. A RevClient component receives C2 commands, can manage user accounts, and forwards attacker traffic to local RDP, with 5.61.59.53:2086 shown as the main C2 endpoint.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 751698edee5ec4c46fddaa995f12098… 2023-10-16 2024-10-01
IPv4 5.61.59.53 2023-10-16 2024-08-22
HASH fd3d5776f820448d30825c73afbfe2b… 2023-10-16 2023-10-17
HASH 2eaea4a3a9fdb7f5c5f00a8ddefde8d… 2023-10-16 2023-10-17
HASH 9d2468e5c289f3d012ad071602e149f… 2023-10-16 2023-10-17
HASH 116a71365b83cc38211ccfc8059b363e 2023-10-16 2023-10-17
HASH ad9a3e893abdac7549a7d66ca32142e8 2023-10-16 2023-10-17
HASH 5553f29418c8b9c6021b8f98e0032fd… 2023-10-16 2023-10-17
HASH ef9007ea0cc0572215b2d57a4321fab… 2023-10-16 2023-10-17
HASH 9f8cf1a7eca196323e0bc0ede6f2da5… 2023-10-16 2023-10-17
URL https://onessearth.online/up/up… 2023-10-16 2023-10-17
URL https://powsecme.co/up/upload_d… 2023-10-16 2023-10-17
DOMAIN onessearth.online 2023-10-16 2023-10-17
DOMAIN powsecme.co 2023-10-16 2023-10-17

Related Actors

Related Reports

« Back