SilverFox: Tracking the Distribution of a Domestic Variant of a Malicious Installation File Posing as KakaoTalk

SilverFox: Tracking the Distribution of a Domestic Variant of a Malicious Installation File Posing as KakaoTalk
  • The threat actor used SEO poisoning (a technique that exploits search results to redirect users to fake sites) to distribute a malicious installer disguised as a KakaoTalk installer.
  • The appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup. It contained both legitimate installation files and malicious files.
  • When a user ran the disguised installation file, shellcode (code loaded into memory and executed) was triggered, and the malicious payload was executed.
  • Initially, the attackers patched legitimate files signed with valid digital certificates to execute shellcode. In recent variants, the tactic shifted to DLL side-loading (a technique where a legitimate program loads a malicious DLL).
  • A notable example involved the use of javacpl.Exe (Java Control Panel), where deploy.Dll was loaded as a malicious DLL and then connected to a C2 server to download ValleyRAT.
  • The shellcode loading methods have also continued to evolve, including the use of sRDI, Donut Loader, the addition of XOR operations, a shift from CreateFile to VirtualAlloc-based loading, and the application of code virtualization.
  • The shellcode in the latest variants used steganography (a technique for concealing information) to hide the code in an encrypted form inside a PNG file.
  • Malicious file names and creation paths consisted of random strings, and instances were confirmed where random strings were generated using the external web service hxxp://www.Qmsjmfb.Com.
  • In the latest variant, the malicious file was created in the C:\msys64 Path, registered as a Service, and executed; the final payload was identified as Ghost.
  • Damaix9k[.]Com, which the sample accessed, matched infrastructure previously reported as a Ghost C2 server that had delivered MODBEACON.
  • The report mentioned the possibility that this activity is linked to the SilverFox/UTG-Q-1000 ecosystem but stated that the identity of the attack actor cannot be definitively determined based solely on the similarity of the C2 infrastructure.
  • The key TTPs identified are T1608.006, T1036, T1204.002, T1620, T1055, and T1027.
  • In terms of mitigation, users should not rely solely on search results; they must verify the source by visiting the official KakaoTalk website to download the installation file. Additionally, they should check for the presence of malware in the following paths—%APPDATA%\comainev2f79\, %APPDATA%\KakaoTalkSetup\, and C:\msys64\* and delete any malware found in the Malware Path.

MD5

23926d9ea06eb774ff65f103336f3365
3236a086ccb22648a9c2a620266d7fc3
36706dd0e9b395a6d9b2fa4f65548f5b
4308d97bf2336ce03287df849c808390
4acca854c069933a3f535dee6d1be9af
URL

http[:]//47[.]243[.]52[.]192/NewFile/deploy[.]dll
http[:]//dajinkb[.]gwyj[.]eu[.]cc/
http[:]//dajinkb2[.]gwyj[.]eu[.]cc/
http[:]//dajintest[.]oss-ap-southeast-6[.]aliyuncs[.]com/log/config[.]dat
http[:]//damaix9k[.]com/