钓鱼之王 —— Kimsuky近期以多个话题针对韩国的鱼叉式钓鱼攻击活动分析

2022-07-25 Qianxin King of Phishing: Analysis of recent Kimsuky spear-phishing attacks against South Korea using multiple themes

https://ti.qianxin.com/blog/articles/king-of-phishing-analysis-of-kimsuky's-recent-spear-phishing-attacks-targeting-south-korea-with-multiple-topics/

Thumbnail for 钓鱼之王 —— Kimsuky近期以多个话题针对韩国的鱼叉式钓鱼攻击活动分析

Qianxin attributes with medium confidence a set of spear-phishing attacks against South Korean targets to Kimsuky, noting the group's focus on defense, education, energy, government, healthcare, and think tanks. The campaign used HWP lure documents themed around North Korean defector advisory surveys, Korea Policy Broadcasting invitations, and North Korea COVID-19 analysis to induce user interaction and execute embedded OLE or EPS content. The execution chain dropped temporary files, ran PowerShell, injected MSF-generated shellcode into legitimate Windows processes such as help.exe or winhlp32.exe, and used fileless follow-on loading to reduce detection. One sample used mshta.exe and a scheduled task named EstSoft\Alcap\Report to periodically contact C2, parse returned commands, execute them via cmd.exe, and post results back. Reported indicators include MD5 hashes such as 905745E2A196D7F8D7C2F9547F5B9E67 and infrastructure including hanainternational.net and work3.b4a.app.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 905745e2a196d7f8d7c2f9547f5b9e67 2022-07-25 2022-09-03
HASH 8b9ea99a52c995d299e25df2ab24175d 2022-07-25 2022-07-25
HASH a5e4d92c27fb4f8308f77a3833451801 2022-07-25 2022-07-25
HASH 29307065fc17ba422c93b790ac723a90 2022-07-25 2022-07-25
URL https://work3.b4a.app/download.… 2022-06-20 2022-07-25
URL http://hanainternational.net/ed… 2022-06-01 2022-07-25
DOMAIN hanainternational.net 2022-05-09 2022-07-25

Related Actors

Related Reports

« Back