Rewterz Threat Alert – Beware of The IcedID Malware That Uses Contact Forms
April 13, 2021Rewterz Threat Advisory – New Exploit Released for Unpatched Google Chrome And Microsoft Edge
April 13, 2021Rewterz Threat Alert – Beware of The IcedID Malware That Uses Contact Forms
April 13, 2021Rewterz Threat Advisory – New Exploit Released for Unpatched Google Chrome And Microsoft Edge
April 13, 2021Severity
High
Analysis Summary
Kimsuky is believed to be a North Korean-based threat group who have been operating since the latter half of 2013 with many campaigns being attributed to the group. The group is also known by other names including Velvet Chollima and Black Banshee. The group is using filename of autoupdate.dll is to push the users to download the malicious file which will install the malicious dll to gain access of the victim’s system.
Impact
Information Theft and Espionage
Indicators of Compromise
Filename
autoupdate[.]dll
MD5
a03598cd616f86998daef034d6be2ec5
SHA-256
fa4d05e42778581d931f07bb213389f8e885f3c779b9b465ce177dd8750065e2
SHA1
4175be93e7221d088a5f72a191f237aa7fb07965
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.