Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

2024-07-01 • Ahnlab •

https://asec.ahnlab.com/en/67558/

Thumbnail for Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

ASEC observed attacks against Korean defense and manufacturing organizations in which a threat actor abused a Korean ERP solution and compromised Windows IIS web servers to deploy Xctdoor and XcLoader. The ERP case resembles earlier Andariel tradecraft from 2017, where a malicious routine was inserted into an ERP updater to distribute the HotCroissant backdoor, but the recent activity is described as involving an unidentified threat actor. Xctdoor is a Go-based DLL backdoor executed through Regsvr32.exe, injected into normal processes, and persisted through files under a Microsoft Edge package path and a startup shortcut. Its capabilities include system profiling, command execution, screenshot capture, keylogging, clipboard logging, drive information collection, and HTTP C2 using Mersenne Twister and Base64-based encryption. The web-server cases involved XcLoader installation, command execution consistent with possible web-shell access, and Ngrok use to expose RDP access, making the activity significant for tracking ERP supply-chain abuse and DPRK-linked Andariel-adjacent techniques in Korean enterprises.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9bbde4484821335d98b41b44f93276e8 2024-06-24 2024-07-01
HASH c61eca8cf14ce18a54616c3bbe17973… 2024-06-24 2024-07-01
HASH f24627f46ec64cae7a6fa9ee312c43d7 2024-06-24 2024-07-01
HASH 41d5d25de0ca0fdc54c24c484f9f8f55 2024-06-24 2024-07-01
HASH 2e325935b2d1d0a82e63ff2876482956 2024-06-24 2024-07-01
HASH 1417416ba94d9a0f3c34be4c529c244… 2024-06-24 2024-07-01
HASH 3e7715ac57003f8a80119ab348a7a7b… 2024-06-24 2024-07-01
HASH 375f1cc32b6493662a78720c7d905bc3 2024-06-24 2024-07-01
HASH 6928fab25ac1255fbd8d6c1046653919 2024-06-24 2024-07-01
HASH ab8675b4943bc25a51da66565cfc8ac8 2024-06-24 2024-07-01
HASH 934622b6a764a3b4f2a0049c62e66b9… 2024-06-24 2024-07-01
HASH a42ae44761ce3294ce0775fe384d97b6 2024-06-24 2024-07-01
HASH 3d4b90f520ed82ef886f0a38e1a621e… 2024-06-24 2024-07-01
HASH d938201644aac3421df7a3128aa88a53 2024-06-24 2024-07-01
HASH e554b1be8bab11e979c75e2c2453bc6a 2024-06-24 2024-07-01
HASH 54d5be3a4eb0e31c0ba7cb88f0a8e720 2024-06-24 2024-07-01
HASH ad96a8f22faab8b9c361cfccc381cd28 2024-06-24 2024-07-01
HASH 11465d02b0d7231730f3c4202b0400b8 2024-06-24 2024-07-01
HASH 9974b4befa2906a6925e786c4765131… 2024-06-24 2024-07-01
HASH b43a7dcfe53a981831ae763a9a5450fd 2024-06-24 2024-07-01
HASH 4f5e5a392b8a3e0cb32320ed1e8d0604 2024-06-24 2024-07-01
HASH 09a5069c9cc87af39bbb6356af2c1a36 2024-06-24 2024-07-01
URL http://www.jikji.pe.kr/xe/files… 2024-06-24 2024-07-01
URL http://beebeep.info/index.php 2024-06-24 2024-07-01
DOMAIN beebeep.info 2024-06-24 2024-07-01
IPv4 195.50.242.110 2024-06-24 2024-07-01

Related Actors

First seen: Jul 2017
Last seen: Sep 2026

Related Reports

2024-07-25 • 48% Match
#Andariel #Maui #MoneyLaundering #ArkansasHealthcare #CaliforniaDefense #ChineseEnergy #ColoradoMedical #ConnecticutHealthcare #FloridaHospital #KansasHospital #MassachusettsDefense #MichiganDefense #NASA #OregonDefense #RandolphAirForce #RobinsAirForce #SouthKoreanManufacturing #TaiwaneseDefense
Shares tag: Andariel • Published within a month
« Back