RDP를 이용해 감염 시스템을 제어하는 Kimsuky 위협 그룹

2023-10-16 • Ahnlab • Kimsuky threat group controls infected systems using RDP •

https://asec.ahnlab.com/ko/57748/

Thumbnail for RDP를 이용해 감염 시스템을 제어하는 Kimsuky 위협 그룹

AhnLab describes Kimsuky intrusions that use presumed spear phishing to install BabyShark and then add RDP-focused tooling for hands-on control of infected Windows systems. The activity includes hwp.bat, PowerShell keylogging through k.ps1 and OneNote.vbs, loaders such as pow.ps1 and desktop.r7u, and injector behavior tied to xRAT or related malware in earlier cases. Follow-on payloads include multiple.exe, which modifies termsrv.dll, enables multiple RDP sessions, creates a hidden IIS_USER administrator account, and supports stealthier remote access. A newer RevClient component receives C2 commands, can add or hide accounts, and forwards attacker traffic to local RDP through 5.61.59.53:2086.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 751698edee5ec4c46fddaa995f12098… 2023-10-16 2024-10-01
IPv4 5.61.59.53 2023-10-16 2024-08-22
HASH fd3d5776f820448d30825c73afbfe2b… 2023-10-16 2023-10-17
HASH 2eaea4a3a9fdb7f5c5f00a8ddefde8d… 2023-10-16 2023-10-17
HASH 9d2468e5c289f3d012ad071602e149f… 2023-10-16 2023-10-17
HASH 116a71365b83cc38211ccfc8059b363e 2023-10-16 2023-10-17
HASH ad9a3e893abdac7549a7d66ca32142e8 2023-10-16 2023-10-17
HASH 5553f29418c8b9c6021b8f98e0032fd… 2023-10-16 2023-10-17
HASH ef9007ea0cc0572215b2d57a4321fab… 2023-10-16 2023-10-17
HASH 9f8cf1a7eca196323e0bc0ede6f2da5… 2023-10-16 2023-10-17
URL https://onessearth.online/up/up… 2023-10-16 2023-10-17
URL https://powsecme.co/up/upload_d… 2023-10-16 2023-10-17
DOMAIN onessearth.online 2023-10-16 2023-10-17
DOMAIN powsecme.co 2023-10-16 2023-10-17

Related Actors

Related Reports

« Back