Go-ing arsenal: a closer look at Kimsuky’s Go strategic advancement

No ratings

Presented at Virus Bulletin 2024 by

Kimsuky Group (a.k.a. APT43), a North Korean APT group, has been active since at least 2013, initially targeting government departments in South Korea, but has since expanded its targets around the world, including the United States, Russia and Europe. In particular, AppleSeed, a backdoor-type malware that was developed and used by the Kimsuky group, was first discovered in 2019 and has been circulating in various structural and functional variations since then. S2W's threat research and intelligence centre, Talon, has identified additional samples exhibiting similarities to the previously known AppleSeed during its ongoing tracking of the Kimsuky group's activities. S2W Talon has named these malware samples BetaSeed (backdoor), AlphaSeed (backdoor), GoBear (backdoor) and Troll Stealer, respectively, based on the chronological order of their discovery. Unlike AlphaSeed, the Go variant of AppleSeed, the attack techniques and strategies used in BetaSeed, GoBear, and Troll Stealer are distinct from those associated with the Kimsuky group in the past. The fact that the Kimsuky group has not been known to hijack GPKI folders or exploit the SOCKS5 protocol indicates that they may have changed their targets, or that another group with access to the source code of AppleSeed and AlphaSeed has developed BetaSeed, GoBear and Troll Stealer. We categorized the Kimsuky group's new malware based on functionality and type. In our presentation, we will delve into the behaviour of each malware type and share recent attack cases. During the analysis, we confirmed that all malware except BetaSeed was written in Go. This aligns with the Kimsuky group's recent trend of utilizing Go-based tools and malware. In light of this, we will delve into their new Go strategy. We anticipate that by providing the TTPs and latest Go strategy employed by the Kimsuky group, we can offer actionable items that can aid in responding to similar threat incidents should they arise