Piece of dragon's scales
2021-12-30 • kino •
A Korean malware-analysis post tracks ongoing Kimsuky/Thallium activity using the GoldDragon/BravePrince cluster, noting a newer sample that keeps the usual daum-mail information-theft behavior while adding encoded DLL and API-name resolution. The author also describes a related information-stealer module that collects system, network, process, file-list, and browser credential data into an AppData working directory and appears designed to be launched by another component. A third case links the same encoded-string intelligence pivot to a .NET dropper that deploys privilege-elevation tooling, disables Windows Defender, installs a Quasar RAT-based payload, and persists through scheduled tasks or Run keys. Representative infrastructure and indicators include blog.daum[.]net/casalesmedia/pages/category, 222.122.79.232 on ports 8080 and 443, and hashes for the analyzed samples.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 237deba138355bfb448e74bfb68fc86… | 2021-12-30 | 2021-12-30 |
| HASH | 0cf7e1268e8652d841b7bda784707e4… | 2021-12-30 | 2021-12-30 |
| HASH | 51a92bd57ece4a107dacabf2639b6fa… | 2021-12-30 | 2021-12-30 |
| HASH | 3903958eb28632aa58e455eb87482d1… | 2021-12-30 | 2021-12-30 |
| IPv4 | 222.122.79.232 | 2021-12-30 | 2021-12-30 |
| IPv4 | 14.47.189.243 | 2021-12-30 | 2021-12-30 |
| HASH | 5e3907e9e2ed8ff12bb4e96b52401d8… | 2021-11-10 | 2021-12-30 |