MAR-10301706-2.v1 - North Korean Remote Access Tool: VIVACIOUSGIFT
2020-08-26 • USCISA •
DHS, FBI, and DoD identified VIVACIOUSGIFT as a Windows remote-access and network-proxy tool used by the North Korean government under the U.S. HIDDEN COBRA designation. The malware decrypts command-line configuration containing source, destination, and optional upstream-proxy settings, then receives commands to set its destination and relay encrypted traffic. CISA published six sample hashes, a YARA rule, and Snort signatures for the proxy protocol and encrypted command strings.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | CISA_3P_10301706_02 | 2020-08-26 | 2020-08-26 |
| HASH | aca598e2c619424077ef8043cb42847… | 2020-08-26 | 2020-08-26 |
| HASH | 70b494b0a8fdf054926829dcb3235fc… | 2020-03-09 | 2020-08-26 |
| HASH | 9a776b895e93926e2a758c09e341acc… | 2019-01-23 | 2020-08-26 |
| HASH | f3ca8f15ca582dd486bd78fd57c2f4d… | 2018-07-23 | 2020-08-26 |
| HASH | 8cad61422d032119219f465331308c5… | 2017-02-20 | 2020-08-26 |
| HASH | a917c1cc198cf36c0f2f6c24652e5c2… | 2017-02-16 | 2020-08-26 |
Related Actors
Related Reports
Shares tags: YARA, HiddenCobra • Same author: USCISA • Published within a week
Shares tags: YARA, HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tags: YARA, HiddenCobra • Same author: USCISA
Shares tags: YARA, HiddenCobra • Same author: USCISA
Shares tags: YARA, HiddenCobra • Same author: USCISA