김수키(Kimsuky)삼성전자 미팅 관련 으로 제작 악성코드(2025.9.11)
2025-09-17 • Sakai • Malware Created by Kimsuky Related to a Samsung Electronics Meeting (2025.9.11) •
A Kimsuky-attributed LNK masquerades as a Samsung Electronics meeting-related PDF and launches hidden PowerShell to decode and run a temporary script. The infection chain downloads a decoy PDF and additional scripts from raw.githubusercontent.com under the entire73/leedohun path, stores payloads such as chrome.ps1, temp.ps1, and system_first.ps1 under temporary or AppData locations, and registers a scheduled task for persistence. The lure content references Samsung Global Public Affairs meeting topics around U.S.-China relations, Indo-Pacific strategy, tariffs, and Korean security cooperation, suggesting interest in policy and external-affairs targets. The use of GitHub raw content, a hard-coded GitHub token, hidden PowerShell execution, and recurring scheduled-task execution gives defenders concrete behavioral and infrastructure indicators to hunt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e0d6de68f6bad27f668a6da26a6a8cb… | 2025-09-17 | 2025-09-17 |
| HASH | 21a20215102f44ee2f47c21791ec5e6… | 2025-09-17 | 2025-09-17 |
| HASH | f2d65a516a9f68487f1fb417f0f20314 | 2025-09-17 | 2025-09-17 |
| DOMAIN | sercontent.com | 2025-09-17 | 2025-09-17 |
| IPv4 | 45.32.133.19 | 2025-09-08 | 2025-09-17 |