#DurianBeacon

Malware/Tool

2024-05-27 • 국내 기업 대상 공격에 사용 중인 SmallTiger 악성코드 (Kimsuky, Andariel 그룹)

DurianBeacon is a remote access Trojan previously observed in Andariel operations and installed as the final backdoor during attacks against South Korean defense, automotive-parts, and semiconductor businesses in November 2023. The intrusions included tools associated with Kimsuky, such as MultiRDP, Meterpreter, and Ngrok, but differed from typical Kimsuky activity by abusing company software updater programs for internal propagation. MultiRDP enabled covert additional RDP logins, while Meterpreter supported command execution, information theft, and lateral movement before DurianBeacon was deployed. Similar C2 infrastructure and tooling suggested Kimsuky links, whereas DurianBeacon's prior Andariel use made the campaign's operator relationship notable but not conclusively resolved.

Tagged Reports

« Back