Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)
ID: 72668617-6ad9-5237-a01f-b3a1c32e4044
STIX ID: report--72668617-6ad9-5237-a01f-b3a1c32e4044
Feed Name: ASEC
Threat Score
ASEC identified renewed Andariel activity targeting Korean asset-management and document-management solutions, delivering SmallTiger and ModeLoader, using a unique keylogger that stores keystrokes in MsMpLog.tmp, enabling RDP access and creating hidden backdoor accounts, and deploying web shells via outdated Apache Tomcat instances; the report provides IOCs (45.61.148.153, http://45.61.148.153/pizza.jsp, and several MD5 hashes) and recommends patching and enhanced monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
