Analysis of CoinMiner Attacks Targeting Korean Web Servers
ID: 743a620f-3999-525e-b7c7-1a46f070b247
STIX ID: report--743a620f-3999-525e-b7c7-1a46f070b247
Feed Name: ASEC
AhnLab ASEC observed two web-server intrusion campaigns against a Korean medical institution (likely a PACS-equipped IIS server) where attackers uploaded web shells (Chopper, Behinder, Godzilla, Caidao), used privilege-escalation exploits/tools (BadPotato, GodPotato, PrintNotifyPotato, CVE-2021-1732), deployed tunneling/proxy tools (Cpolar, Frpc, Lcx, EarthWorm) and loaders/injectors (RingQ, Ladon) to ultimately install XMRig CoinMiner; the report includes mining pool addresses, file detections, MD5 hashes and download URLs, and attributes activity to Chinese-speaking actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
