Rewterz
Rewterz Threat Alert – Lokibot Malware – Active IOCs
June 10, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-23392 – Node.js locutus module vulnerabilities
June 11, 2021

Rewterz Threat Alert – APT Group Kimsuky – Active IOCs

Severity

Medium

Analysis Summary

Kimsuky is believed to be a North Korean-based threat group who have been operating since the latter half of 2013 with many campaigns being attributed to the group. The group is also known by other names including Velvet Chollima and Black Banshee. Kimsuky employs common social engineering tactics, spearphishing, and watering hole attacks to exfiltrate desired information from victims. Kimsuky usually conducts its intelligence collection activities against individuals and organizations in South Korea, Japan, and the United States. Kimsuky focuses its intelligence collection activities on foreign policy and national security issues related to the Korean peninsula, nuclear policy, and sanctions.

Impact

  • Remote Access Connections
  • Watering hole attacks
  • Keyloggers

Indicators of Compromise

MD5

  • d4da4660836d61db95dd91936e7cfa4a
  • 815c690bfc097b82a8f1d171cd00e775
  • 7f4624a8eb740653e2242993ee9e0997
  • 6e8406d6680899937f23c788a7008a11

SHA-256

  • 8828848abd439698aed441197e455be2b09f18845cd2ee83ebd6b5a486b8cdd4
  • 6184acd90c735783aafd32c3346c94332fa8c0212ec128a61f2764bd224c2535
  • 12c9f6699f64c757aebf5d9120d95a612826bee0ffe7676812b28bd31e86c9c0
  • dd40c10edb977915dbda58c61d2607528f2757d0411d9f4afc813ed315a59689

SHA1

  • 1927b0ccd6f8982e74a2523c6ca4cd41093d79e6
  • fe301ca0bee41580ff1d06a2c33c63cc0a033637
  • 0aa04d97417a72ac3f5949c496244170495d495e
  • 6ca8030f255cebace43a6e2fac0564785daa8440

Remediation

  • Block all threat indicators at your respective controls
  • Search for IOCs in your environment
  • Enable two-factor authentication