#GreenDinosaur

Malware/Tool

2024-08-07 • APT Group Kimsuky Targets University Researchers

Green Dinosaur is an obfuscated PHP webshell staged by Kimsuky on compromised infrastructure used to target university researchers. Derived from Indrajith Mini Shell 2.0, it retains functions for uploading, downloading, renaming, and deleting files while removing other functionality to reduce detection and support deployment of phishing websites. Samples use multiple layers of Base64 encoding and gzip-deflated strings, followed by a final layer combining Base64 with multi-character substitution through PHP's strtr function. Operators use the webshell to upload prebuilt phishing pages scraped from legitimate portals and modified to capture credentials. Observed pages impersonated Dongduk University, Korea University, Yonsei University, and Naver services.

Tagged Reports

« Back