HomeSecurityKimsuky: Uses RAT with customized Gold Dragon malware

Kimsuky: Uses RAT with customized Gold Dragon malware

Researchers from South Korea have identified new activity from the hacking group Kimsuky, which includes open-source remote access tools with customized Gold Dragon malware.

Kimsuky

See also: North Korean hackers tried to interfere with vaccine trials

Kimsuky is a North Korean state-backed hacking group , also known as TA406 , which has been actively involved in cyber espionage campaigns since 2017.

The group has demonstrated impressive operational flexibility and has a wide range of activities, engaging in malware distribution, phishing, data collection, and even cryptocurrency theft.

In its latest operation, detected by analysts at ASEC (AhnLab), Kimsuky is using xRAT in targeted attacks against South Korean organizations. The campaign began on January 24, 2022 and is still ongoing.

xRAT is an open-source remote access and administration tool available for free on GitHub. The malware provides a range of features, including keystroke logging, remote shell, file management actions, HTTPS reverse proxy, AES-128 communication, and automated social engineering.

A sophisticated threat actor may choose to use RATs as for basic reconnaissance operations, these tools are perfectly adequate and do not require much configuration.

See also: APT37 targets South Korean journalists with Chinotto malware

This allows malicious users to focus their resources on developing later-stage malware, which requires more specialized functionality depending on the defensive tools/practices in place.

Golden Dragon

Also, RATs are combined with activity from a wide range of threat actors, making it more difficult for analysts to attribute malicious activity to a specific group.

Gold Dragon is a second-stage backdoor that Kimsuky typically deploys after a first-stage attack that is fileless PowerShell-based and leverages steganography.

However, as ASEC explains in its report, the variant detected this time has additional functions, such as extracting basic system information.

The malware no longer uses system processes for this operation, but instead installs the xRAT tool to steal the necessary information manually.

The RAT is disguised as an executable, named cp1093.exe, which copies a regular PowerShell process (powershell_ise.exe) to the path “C:\ProgramData\” and executes via a hollowing process.

See also: Hackers infected with their own RAT malware

The installer then adds a new registry key to specify boot persistence for the malware payload (glu32.dll).

Finally, the team drops an uninstaller (UnInstall_kr5829.co.in.exe) that can delete traces of the breach if and when needed.

AhnLab recommends that users refrain from opening email attachments from unknown sources, as this remains the main malware distribution channel for Kimsuky.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS