Rewterz Threat Alert – Lokibot Malware – Active IOCs
June 10, 2021Rewterz Threat Advisory – CVE-2021-23392 – Node.js locutus module vulnerabilities
June 11, 2021Rewterz Threat Alert – Lokibot Malware – Active IOCs
June 10, 2021Rewterz Threat Advisory – CVE-2021-23392 – Node.js locutus module vulnerabilities
June 11, 2021Severity
Medium
Analysis Summary
Kimsuky is believed to be a North Korean-based threat group who have been operating since the latter half of 2013 with many campaigns being attributed to the group. The group is also known by other names including Velvet Chollima and Black Banshee. Kimsuky employs common social engineering tactics, spearphishing, and watering hole attacks to exfiltrate desired information from victims. Kimsuky usually conducts its intelligence collection activities against individuals and organizations in South Korea, Japan, and the United States. Kimsuky focuses its intelligence collection activities on foreign policy and national security issues related to the Korean peninsula, nuclear policy, and sanctions.
Impact
- Remote Access Connections
- Watering hole attacks
- Keyloggers
Indicators of Compromise
MD5
- d4da4660836d61db95dd91936e7cfa4a
- 815c690bfc097b82a8f1d171cd00e775
- 7f4624a8eb740653e2242993ee9e0997
- 6e8406d6680899937f23c788a7008a11
SHA-256
- 8828848abd439698aed441197e455be2b09f18845cd2ee83ebd6b5a486b8cdd4
- 6184acd90c735783aafd32c3346c94332fa8c0212ec128a61f2764bd224c2535
- 12c9f6699f64c757aebf5d9120d95a612826bee0ffe7676812b28bd31e86c9c0
- dd40c10edb977915dbda58c61d2607528f2757d0411d9f4afc813ed315a59689
SHA1
- 1927b0ccd6f8982e74a2523c6ca4cd41093d79e6
- fe301ca0bee41580ff1d06a2c33c63cc0a033637
- 0aa04d97417a72ac3f5949c496244170495d495e
- 6ca8030f255cebace43a6e2fac0564785daa8440
Remediation
- Block all threat indicators at your respective controls
- Search for IOCs in your environment
- Enable two-factor authentication