Researchers Track Malware Distributed Through Fake KakaoTalk Installers

· Original article ↗

Summary

AhnLab traces SEO-poisoned fake KakaoTalk installers using evolving loading techniques to deliver ValleyRAT and Ghost. Similarity to known C2 infrastructure suggests a possible SilverFox/UTG-Q-1000 link, but does not confirm attribution.

Key points

  • SEO poisoning directed users to fake KakaoTalk sites offering malicious installers packaged with NSIS, Advanced Installer, or Inno Setup.
  • Early variants patched legitimately signed files to run shellcode; later versions used DLL side-loading, including a malicious deploy.dll loaded by Java Control Panel.
  • One side-loading chain contacted a C2 server to download ValleyRAT; a more recent variant installed and ran Ghost as a service from C:\msys64.
  • The shellcode-loading methods evolved to include sRDI, Donut Loader, XOR operations, VirtualAlloc-based loading, code virtualization, and code concealed in an encrypted PNG.
  • The activity may be linked to the SilverFox/UTG-Q-1000 ecosystem based on C2 infrastructure similarities, but the report says the actor cannot be definitively identified.
  • AhnLab advises downloading KakaoTalk only from its official website and checking specified AppData and C:\msys64 paths for malware.

Article Details

Attack Vectors
  • The attacker used SEO poisoning to direct users to fake sites distributing an installer disguised as KakaoTalk.
  • Running the disguised installer triggered shellcode and executed a malicious payload. The package contained both legitimate installation files and malicious files.
  • Earlier variants patched legitimately signed files to execute shellcode. Later variants used DLL side-loading; one example used javacpl.Exe to load a malicious deploy.Dll, connect to C2 infrastructure, and download ValleyRAT.
  • The latest described variant concealed encrypted shellcode in a PNG file using steganography, then created a malicious file under C:\msys64, registered it as a service, and executed it. The final payload was identified as Ghost.
Defensive Notes
  • Do not rely solely on search results for a KakaoTalk installer; visit the official KakaoTalk website to verify the download source.
  • Check %APPDATA%\comainev2f79\, %APPDATA%\KakaoTalkSetup\, and C:\msys64\* for malware, and delete any malware found.

Indicators of compromise

TypeIndicatorContext
DOMAINdamaix9k[.]comDomain accessed by the sample that matched previously reported Ghost C2 infrastructure used to deliver MODBEACON.
MD523926d9ea06eb774ff65f103336f3365MD5 listed in the report's malware indicators.
MD53236a086ccb22648a9c2a620266d7fc3MD5 listed in the report's malware indicators.
MD536706dd0e9b395a6d9b2fa4f65548f5bMD5 listed in the report's malware indicators.
MD54308d97bf2336ce03287df849c808390MD5 listed in the report's malware indicators.
MD54acca854c069933a3f535dee6d1be9afMD5 listed in the report's malware indicators.
URLhxxp[:]//47[.]243[.]52[.]192/NewFile/deploy[.]dllMalicious DLL URL listed in the report's indicators.
URLhxxp[:]//dajinkb[.]gwyj[.]eu[.]cc/Threat-infrastructure URL listed in the report's indicators.
URLhxxp[:]//dajinkb2[.]gwyj[.]eu[.]cc/Threat-infrastructure URL listed in the report's indicators.
URLhxxp[:]//dajintest[.]oss-ap-southeast-6[.]aliyuncs[.]com/log/config[.]datSpecific cloud-hosted resource URL listed in the report's threat indicators.
URLhxxp[:]//damaix9k[.]com/URL listed in the report's indicators; its domain was previously reported as Ghost C2 infrastructure.

MITRE ATT&CK

Threat Actors

Malware

Products

Tools

Related Articles