Infostealer Disguised as Copyright Infringement Document Distributed in Korea

Infostealer Disguised as Copyright Infringement Document Distributed in Korea

Infostealer malware disguised as legal and copyright infringement documents is actively distributed in Korea via email attachments, employing DLL Side-Loading and double extension techniques to evade detection. The malware targets sensitive user information, exfiltrating data related to emails, FTP, banking, and browser credentials to remote servers. #Rhadamanthys #Infostealer #DLLSideLoading #DoubleExtension

Keypoints

  • Infostealer malware disguised as documents on legal responsibilities and copyright infringement is distributed through email attachment links in Korea.
  • Two main execution methods are used: DLL Side-Loading, involving malicious DLLs loaded by legitimate EXE files, and double extension disguising EXE files as document files.
  • The DLL Side-Loading method uses legitimate PDF Reader EXE and malicious DLLs to inject Rhadamanthys Infostealer into system processes for data exfiltration.
  • The double extension method uses EXE files disguised as PDFs and a text file prompting execution, then uses PowerShell commands to kill security-related processes.
  • The malware targets sensitive information including email, FTP, online banking credentials, browser accounts, and captures screens, sending data to threat actors’ servers.
  • Similar Infostealer campaigns using copyright infringement-themed file names have been detected in Thailand, Hungary, Portugal, Greece, and Japan.
  • Users are advised to avoid executing suspicious email or messenger files, as even legitimate programs may load malicious DLLs leading to compromise.

MITRE Techniques

  • [T1073] DLL Side-Loading – Loaded malicious DLLs alongside legitimate executables to execute Rhadamanthys Infostealer (“malicious DLL is loaded when the legitimate application is run”).
  • [T1059] Command and Scripting Interpreter – Used PowerShell commands to terminate security tools and avoid detection (“Infostealer uses a Powershell command to terminate a specific process”).
  • [T1055] Process Injection – Injected malicious code into legitimate Windows system processes such as openwith.exe and rundll32.exe (“Rhadamanthys performs DLL injection into legitimate Windows system programs”).
  • [T1204] User Execution – Trick users into executing disguised files with double extensions and misleading file names (“EXE file is disguised as a PDF document using a double extension”).
  • [T1566] Phishing – Distributed malware via email attachments with links prompting download of supposed copyright infringement evidence (“distributed through links in email attachments, email instructs … to download the evidence”).

Indicators of Compromise

  • [File Hash] Examples of malware file MD5 hashes – 64a145f3716c4fae76389ced81013e28, ca58a723609057048c97ebd8f9b4d36f
  • [URL] Malicious distribution links – hxxps://tr[.]ee/3FKnsw, hxxps://laurayoung2169944-dot-yamm-track.appspot[.]com/2gwdQgyj0E2vzqvbGg2Q8Vfawz52qe38tVH-Y92ZoVgBqJibClgEzOCbYyqGbTJh0dKhw8GQbFcFesz7f9zrLq-2V-eP1KMh9AEWIYxXvJBaYeQMZELdDvNm3D-jXjmCZhpzvekp6k6wRmVhQAy8E8tvBKAmido8oujb3kXgIEfYHLKv2LcSBPU3qzwd3tG0yoQroSnpBWvxoJ0Cigir-WRpFZtmNqF9GzWiYvcbQYCAFW112o2ZfGIvFBZS2YBmvm5iJcYtbCXPbhF_PffE2uiWA
  • [File Name] Suspicious distributed compressed file names – “Definite evidence helps to confirm the criminal behavior.zip”, “Evidence and Detailed Information on Copyright Infringement.zip”


Read more: https://asec.ahnlab.com/en/88544/