MAR-10301706-2.v1 - North Korean Remote Access Tool: VIVACIOUSGIFT

2020-08-26 • USCISA •

https://www.cisa.gov/news-events/analysis-reports/ar20-239b

Thumbnail for MAR-10301706-2.v1 - North Korean Remote Access Tool: VIVACIOUSGIFT

DHS, FBI, and DoD identified VIVACIOUSGIFT as a Windows remote-access and network-proxy tool used by the North Korean government under the U.S. HIDDEN COBRA designation. The malware decrypts command-line configuration containing source, destination, and optional upstream-proxy settings, then receives commands to set its destination and relay encrypted traffic. CISA published six sample hashes, a YARA rule, and Snort signatures for the proxy protocol and encrypted command strings.

Indicators of Compromise

Type Value First Seen Last Seen
YARA CISA_3P_10301706_02 2020-08-26 2020-08-26
HASH aca598e2c619424077ef8043cb42847… 2020-08-26 2020-08-26
HASH 70b494b0a8fdf054926829dcb3235fc… 2020-03-09 2020-08-26
HASH 9a776b895e93926e2a758c09e341acc… 2019-01-23 2020-08-26
HASH f3ca8f15ca582dd486bd78fd57c2f4d… 2018-07-23 2020-08-26
HASH 8cad61422d032119219f465331308c5… 2017-02-20 2020-08-26
HASH a917c1cc198cf36c0f2f6c24652e5c2… 2017-02-16 2020-08-26

Related Actors

Related Reports

« Back