Andariel Group Exploiting Korean Asset Management Solutions (MeshAgent)
ID: 36c817ee-1eba-5c05-acf2-54051ff528eb
STIX ID: report--36c817ee-1eba-5c05-acf2-54051ff528eb
Feed Name: ASEC
Threat Score
AhnLab ASEC reports active Andariel group attacks against South Korean companies that abuse asset-management solutions to deliver loaders (AndarLoader, ModeLoader), deploy MeshAgent for remote control, and install credential-theft tools (Mimikatz) and a keylogger; the report includes behavioral details, commands observed, C2 URLs, MD5 hashes and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
