#ModeLoader

Malware/Tool

2024-03-11 • 국내 자산 관리 솔루션을 악용하여 공격 중인 Andariel 그룹 (MeshAgent)

ModeLoader is malware used by the Andariel group in attacks on South Korean companies. The operators abused domestic asset-management solutions during lateral movement and executed Mshta commands that downloaded and ran ModeLoader inside an Mshta process. Once active, it contacted its C2 server periodically and was used as a backdoor to control infected systems and install additional malware from external sources. Related activity enabled RDP services, apparently used Frpc to reach hosts on private networks, deployed AndarLoader, and installed Mimikatz in attempts to steal credentials. Reported ModeLoader infrastructure used PHP endpoints on several Korean dynamic-hosting domains.

Tagged Reports

« Back