Researchers Track Malware Distributed Through Fake KakaoTalk Installers

Summary
AhnLab traces SEO-poisoned fake KakaoTalk installers using evolving loading techniques to deliver ValleyRAT and Ghost. Similarity to known C2 infrastructure suggests a possible SilverFox/UTG-Q-1000 link, but does not confirm attribution.
Key points
- SEO poisoning directed users to fake KakaoTalk sites offering malicious installers packaged with NSIS, Advanced Installer, or Inno Setup.
- Early variants patched legitimately signed files to run shellcode; later versions used DLL side-loading, including a malicious deploy.dll loaded by Java Control Panel.
- One side-loading chain contacted a C2 server to download ValleyRAT; a more recent variant installed and ran Ghost as a service from C:\msys64.
- The shellcode-loading methods evolved to include sRDI, Donut Loader, XOR operations, VirtualAlloc-based loading, code virtualization, and code concealed in an encrypted PNG.
- The activity may be linked to the SilverFox/UTG-Q-1000 ecosystem based on C2 infrastructure similarities, but the report says the actor cannot be definitively identified.
- AhnLab advises downloading KakaoTalk only from its official website and checking specified AppData and C:\msys64 paths for malware.
Article Details
- Attack Vectors
- The attacker used SEO poisoning to direct users to fake sites distributing an installer disguised as KakaoTalk.
- Running the disguised installer triggered shellcode and executed a malicious payload. The package contained both legitimate installation files and malicious files.
- Earlier variants patched legitimately signed files to execute shellcode. Later variants used DLL side-loading; one example used javacpl.Exe to load a malicious deploy.Dll, connect to C2 infrastructure, and download ValleyRAT.
- The latest described variant concealed encrypted shellcode in a PNG file using steganography, then created a malicious file under C:\msys64, registered it as a service, and executed it. The final payload was identified as Ghost.
- Defensive Notes
- Do not rely solely on search results for a KakaoTalk installer; visit the official KakaoTalk website to verify the download source.
- Check %APPDATA%\comainev2f79\, %APPDATA%\KakaoTalkSetup\, and C:\msys64\* for malware, and delete any malware found.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | damaix9k[.]com | Domain accessed by the sample that matched previously reported Ghost C2 infrastructure used to deliver MODBEACON. |
| MD5 | 23926d9ea06eb774ff65f103336f3365 | MD5 listed in the report's malware indicators. |
| MD5 | 3236a086ccb22648a9c2a620266d7fc3 | MD5 listed in the report's malware indicators. |
| MD5 | 36706dd0e9b395a6d9b2fa4f65548f5b | MD5 listed in the report's malware indicators. |
| MD5 | 4308d97bf2336ce03287df849c808390 | MD5 listed in the report's malware indicators. |
| MD5 | 4acca854c069933a3f535dee6d1be9af | MD5 listed in the report's malware indicators. |
| URL | hxxp[:]//47[.]243[.]52[.]192/NewFile/deploy[.]dll | Malicious DLL URL listed in the report's indicators. |
| URL | hxxp[:]//dajinkb[.]gwyj[.]eu[.]cc/ | Threat-infrastructure URL listed in the report's indicators. |
| URL | hxxp[:]//dajinkb2[.]gwyj[.]eu[.]cc/ | Threat-infrastructure URL listed in the report's indicators. |
| URL | hxxp[:]//dajintest[.]oss-ap-southeast-6[.]aliyuncs[.]com/log/config[.]dat | Specific cloud-hosted resource URL listed in the report's threat indicators. |
| URL | hxxp[:]//damaix9k[.]com/ | URL listed in the report's indicators; its domain was previously reported as Ghost C2 infrastructure. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe latest shellcode was concealed in encrypted form inside a PNG file; the report also describes XOR operations and code virtualization.T1036 · MasqueradingThe malicious installer was disguised as a KakaoTalk installer; earlier variants also patched legitimately signed files.T1055 · Process InjectionThe report lists this ID among its key TTPs but does not describe the injection mechanics.T1204.002 · Malicious FileThe payload execution chain began when a user ran the disguised installer.T1608.006 · SEO PoisoningThe report identifies this technique among its key TTPs; the attacker used SEO poisoning to distribute a disguised KakaoTalk installer through fake sites.T1620 · Reflective Code LoadingThe report identifies this technique among its key TTPs and describes shellcode loaded into memory and executed.
Threat Actors
SilverFoxThe report raises a possible link to the SilverFox/UTG-Q-1000 ecosystem but says C2 similarity alone cannot definitively establish the attacker's identity.UTG-Q-1000The report raises a possible link to the SilverFox/UTG-Q-1000 ecosystem but says C2 similarity alone cannot definitively establish the attacker's identity.
Malware
GhostIn the latest variant, the malicious file was created in the C:\msys64 Path, registered as a Service, and executed; the final payload was identified as Ghost.MODBEACONDamaix9k[.]Com, which the sample accessed, matched infrastructure previously reported as a Ghost C2 server that had delivered MODBEACON.ValleyRATA notable example involved the use of javacpl.Exe (Java Control Panel), where deploy.Dll was loaded as a malicious DLL and then connected to a C2 server to download ValleyRAT.
Products
Advanced InstallerThe appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup.Inno SetupThe appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup.KakaoTalkSilverFox: Tracking the Distribution of a Domestic Variant of a Malicious Installation File Posing as KakaoTalkNSISThe appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup.
Tools
Donut LoaderThe shellcode loading methods have also continued to evolve, including the use of sRDI, Donut Loader, the addition of XOR operations, a shift from CreateFile to VirtualAlloc-based loading, and the application of codesRDIThe shellcode loading methods have also continued to evolve, including the use of sRDI, Donut Loader, the addition of XOR operations, a shift from CreateFile to VirtualAlloc-based loading, and the application of code