Rewterz
Rewterz Threat Alert – Beware of The IcedID Malware That Uses Contact Forms
April 13, 2021
Rewterz
Rewterz Threat Advisory – New Exploit Released for Unpatched Google Chrome And Microsoft Edge
April 13, 2021

Rewterz Threat Alert – Kimsuky APT group – IOCs

Severity

High

Analysis Summary

Kimsuky is believed to be a North Korean-based threat group who have been operating since the latter half of 2013 with many campaigns being attributed to the group. The group is also known by other names including Velvet Chollima and Black Banshee. The group is using filename of autoupdate.dll is to push the users to download the malicious file which will install the malicious dll to gain access of the victim’s system.

Impact

Information Theft and Espionage

Indicators of Compromise

Filename

autoupdate[.]dll

MD5

a03598cd616f86998daef034d6be2ec5

SHA-256

fa4d05e42778581d931f07bb213389f8e885f3c779b9b465ce177dd8750065e2

SHA1

4175be93e7221d088a5f72a191f237aa7fb07965

Remediation

  • Block all threat indicators at your respective controls. 
  • Search for IOCs in your environment.