#Meterpreter

Malware/Tool

2023-05-15 • Meterpreter를 이용해 웹 서버를 공격하는 Kimsuky 그룹

Meterpreter is a backdoor payload from the Metasploit penetration-testing framework that Kimsuky deployed against a poorly managed or unpatched Windows IIS server at a South Korean architecture company. After breaching the server, the operator made the w3wp.exe process invoke PowerShell to download Meterpreter as C:\programdata\img.dat from an external address. Meterpreter provided control of the compromised server and was then used to install an additional Go-based proxy tool, again through PowerShell. The associated infrastructure included an external host and port, while the proxy appeared intended to enable later RDP access into the infected system.

Tagged Reports

« Back