People looking for the KakaoTalk messenger through a search engine are being steered to fake download sites that deliver remote access malware, according to AhnLab Security Intelligence Center (ASEC), which tracked a variant aimed at users in South Korea. The attackers rely on SEO poisoning, manipulating search results so that a malicious site appears where users expect the real one.
The fake installer carries both legitimate KakaoTalk installation files and malicious ones. What makes the campaign notable is not the lure, which is familiar, but how often the operators changed the malware behind it.
Three installer builders and a shifting loader
ASEC found the packaging kept changing, moving from NSIS to Advanced Installer to Inno Setup. Running the installer triggers shellcode (code loaded straight into memory) that runs the malicious payload. Early versions patched legitimate files signed with valid digital certificates to launch that shellcode. Later versions switched to DLL side-loading, where a legitimate program is made to load a malicious library. In one example the Java Control Panel, javacpl.exe, loaded a malicious deploy.dll, which connected to a command server and downloaded ValleyRAT.
The loading code evolved too. ASEC lists sRDI, Donut Loader, added XOR operations, a move from CreateFile to VirtualAlloc-based loading, and code virtualization. In the newest variants the shellcode is concealed in encrypted form inside a PNG image, a technique known as steganography. File names and paths are random strings, in some cases generated with the help of an external web service.
A Ghost payload and a careful Silver Fox link
In the latest variant the malicious file is written to C:\msys64, registered as a Windows service and run, and the final payload is Ghost. The domain the sample contacted, damaix9k[.]com, matches infrastructure previously reported as a Ghost command server that delivered MODBEACON.
That overlap is why the report mentions a possible connection to the Silver Fox (UTG-Q-1000) ecosystem. It is explicit, though, that similar command and control infrastructure alone is not enough to name the attacker. That caution has precedent: in July ASEC argued that AtlasRAT, another tool tied to Silver Fox, looks like a shared framework rather than one crew's private kit. For a separate campaign against Japanese organisations linked to the group at low to medium confidence, see our June report, and for the wider picture, South Korea's country profile.
Get KakaoTalk only from the official site
ASEC's advice is to stop trusting search results for software downloads and to fetch the installer from the official KakaoTalk website instead. It also lists folders to check for leftover malware, and to clean if anything is found, including %APPDATA%\KakaoTalk Setup\ and C:\msys64\. Defenders can additionally hunt for javacpl.exe loading a deploy.dll from an unexpected location, and for new services pointing into C:\msys64.
Indicators of compromise
- MD5: 23926d9ea06eb774ff65f103336f3365
- MD5: 3236a086ccb22648a9c2a620266d7fc3
- MD5: 36706dd0e9b395a6d9b2fa4f65548f5b
- MD5: 4308d97bf2336ce03287df849c808390
- MD5: 4acca854c069933a3f535dee6d1be9af
- hxxp://47[.]243[.]52[.]192/NewFile/deploy[.]dll
- hxxp://dajinkb[.]gwyj[.]eu[.]cc/
- hxxp://dajinkb2[.]gwyj[.]eu[.]cc/
- hxxp://dajintest[.]oss-ap-southeast-6[.]aliyuncs[.]com/log/config[.]dat
- hxxp://damaix9k[.]com/
The download lure is as old as software itself, but the engineering behind this one keeps moving. Three installer formats, several loading techniques and an image-hidden payload in a single campaign show how much effort the operators are putting into staying ahead of detection.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.