강연의뢰서로 위장한 Kimsuky 그룹 악성코드(MSC, HWP)

2024-09-18 Ahnlab Kimsuky malware disguised as a lecture request (MSC, HWP)

https://asec.ahnlab.com/ko/83239/

Thumbnail for 강연의뢰서로 위장한 Kimsuky 그룹 악성코드(MSC, HWP)

AhnLab reports a Kimsuky-linked spearphishing case that used lecture-request lures with HWP documents and MSC files to download additional malicious components. The source says the malware stores attacker-controlled scripts on the victim PC for repeated execution, enabling possible data theft or follow-on payload delivery. It also notes infrastructure patterns similar to a previous Kimsuky batch-file campaign and describes the use of Google Drive file titles to carry encoded malicious commands.

Related Actors

Related Reports

« Back