BabyShark is a new remote access trojan first seen in November 2018 targeting government organisations. It shares infrastructure associated with previous KimJongRAT and STOLEN PENCIL campaigns.
BabyShark is distributed via targeted email campaigns as a malicious attachment. When opened, the attachment connects to and executes an HTA file from a remote location. This application then makes a series of HTTP GET requests to another location to decode and execute the main BabyShark script.
Once successfully established, BabyShark makes changes to the user’s registry settings to disable future macro warnings and maintain persistence, before executing a series of Windows commands to collect information about the infected system. This information is then encoded and uploaded to a command and control (C2) server. BabyShark has the functionality to perform other commands provided to it from the C2 server, although at the time of publication no other commands have been observed.
Indicators of Compromise
SHA256 File Hashes