Piece of dragon's scales

2021-12-30 • kino •

https://sfkino.tistory.com/80

A Korean malware-analysis post tracks ongoing Kimsuky/Thallium activity using the GoldDragon/BravePrince cluster, noting a newer sample that keeps the usual daum-mail information-theft behavior while adding encoded DLL and API-name resolution. The author also describes a related information-stealer module that collects system, network, process, file-list, and browser credential data into an AppData working directory and appears designed to be launched by another component. A third case links the same encoded-string intelligence pivot to a .NET dropper that deploys privilege-elevation tooling, disables Windows Defender, installs a Quasar RAT-based payload, and persists through scheduled tasks or Run keys. Representative infrastructure and indicators include blog.daum[.]net/casalesmedia/pages/category, 222.122.79.232 on ports 8080 and 443, and hashes for the analyzed samples.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 237deba138355bfb448e74bfb68fc86… 2021-12-30 2021-12-30
HASH 0cf7e1268e8652d841b7bda784707e4… 2021-12-30 2021-12-30
HASH 51a92bd57ece4a107dacabf2639b6fa… 2021-12-30 2021-12-30
HASH 3903958eb28632aa58e455eb87482d1… 2021-12-30 2021-12-30
IPv4 222.122.79.232 2021-12-30 2021-12-30
IPv4 14.47.189.243 2021-12-30 2021-12-30
HASH 5e3907e9e2ed8ff12bb4e96b52401d8… 2021-11-10 2021-12-30

Related Actors

Related Reports

« Back