CHM Malware Stealing User Information Being Distributed in Korea
ID: 707066b4-9b4b-52d9-8096-d379d5bcb3f6
STIX ID: report--707066b4-9b4b-52d9-8096-d379d5bcb3f6
Feed Name: ASEC
AhnLab ASEC identified a CHM-based malware campaign targeting Korean users that uses a multi-stage chain (CHM -> Link.ini -> bootservice.php -> OfficeUpdater service -> loggerservice.php) and fileless techniques to deliver obfuscated PowerShell payloads. The malware collects system and file listings, running process details and anti-malware information, performs keylogging and clipboard capture, persists by registering a service that runs periodically, and exfiltrates data to the attacker; detection is reported as Dropper/CHM.Generic with MD5 b2c74dbf20824477c3e139b48833041b.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
