김수키(Kimsuky)만든 링크 방식 악성코드-Pipelines Profile(2023,01,31)
2023-06-26 • Sakai • Link-based malware created by Kimsuky - Pipelines Profile (2023,01,31) •
The Korean source analyzes a Kimsuky-linked LNK malware sample named “Pipelines Profile,” describing the actor’s use of link-file delivery as macro-based Office attacks became less effective. The oversized LNK launches hidden PowerShell, extracts an embedded PDF lure into the temporary directory, opens it with Microsoft Edge, and writes and executes an additional BAT payload from embedded data. The article links this tradecraft to RokRAT-style activity and notes Kimsuky targeting of South Korean think tanks, industry, nuclear-sector interests, DPRK-related organizations, defectors, former officers, diplomats, and government personnel. It provides hashes for the sample and lists multiple vendor detections for the LNK dropper/runner behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 85e71578ad7fea3c15095b6185b14881 | 2023-05-23 | 2023-07-13 |
| HASH | 5d3e6a8d4bd0cf68c3fc3bdf7836c12… | 2023-06-26 | 2023-06-26 |
| HASH | 6753933cd54e4eba497c48d63c7418a… | 2023-05-01 | 2023-06-26 |