“请问,俄乌冲突将如何影响半岛局势?” APT组织KIMSUKY近期定向攻击活动分析
2022-05-05 • NSFOCUS • Excuse me, how will the conflict between Russia and Ukraine affect the situation on the peninsula?" Analysis of recent targeted attacks by APT organization KIMSUKY •
https://web.archive.org/web/20230327072539/http://blog.nsfocus.net/apt-kimsuky-3/
NSFOCUS attributed a targeted phishing activity to Kimsuky that used the malicious document TBS TV_Qs.doc and likely targeted military experts or commentators focused on Korean Peninsula issues. The lure contained interview questions on the Russia-Ukraine war, North Korean ballistic missile tests, inter-Korean affairs, China-South Korea relations, the new South Korean president, denuclearization, and pressure on North Korea. The infection chain used Office macros to fetch decoy content and antivirus-specific bypass components from dusieme[.]com, then downloaded secur32.dll as a KimAPosT variant for persistence and follow-on execution. The KimAPosT variant hid AhnLab alert windows, dropped and ran VBS code, and used a OneDrive API download flow for later-stage script delivery; by discovery time the final script reportedly only sent victim usernames to ielsems[.]com. The report matters for DPRK tracking because it documents Kimsuky adapting a tested toolchain with AV-aware branching and cloud-hosted payload delivery against policy and military research targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ielsems.com | 2022-05-05 | 2024-05-10 |
| DOMAIN | dusieme.com | 2022-05-05 | 2024-05-10 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/r.php | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | https://ielsems.com/cic/macro.p… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | https://api.onedrive.com/v1.0/d… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/eset/d.php?… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/TBS | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | http://dusieme.com/panda/ca.php… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |
| URL | https://dusieme.com/panda/ca.ph… | 2022-05-05 | 2022-05-05 |