김수키(Kimsuky)삼성전자 미팅 관련 으로 제작 악성코드(2025.9.11)

2025-09-17 Sakai Malware Created by Kimsuky Related to a Samsung Electronics Meeting (2025.9.11)

https://wezard4u.tistory.com/429599

Thumbnail for 김수키(Kimsuky)삼성전자 미팅 관련 으로 제작 악성코드(2025.9.11)

A Kimsuky-attributed LNK masquerades as a Samsung Electronics meeting-related PDF and launches hidden PowerShell to decode and run a temporary script. The infection chain downloads a decoy PDF and additional scripts from raw.githubusercontent.com under the entire73/leedohun path, stores payloads such as chrome.ps1, temp.ps1, and system_first.ps1 under temporary or AppData locations, and registers a scheduled task for persistence. The lure content references Samsung Global Public Affairs meeting topics around U.S.-China relations, Indo-Pacific strategy, tariffs, and Korean security cooperation, suggesting interest in policy and external-affairs targets. The use of GitHub raw content, a hard-coded GitHub token, hidden PowerShell execution, and recurring scheduled-task execution gives defenders concrete behavioral and infrastructure indicators to hunt.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e0d6de68f6bad27f668a6da26a6a8cb… 2025-09-17 2025-09-17
HASH 21a20215102f44ee2f47c21791ec5e6… 2025-09-17 2025-09-17
HASH f2d65a516a9f68487f1fb417f0f20314 2025-09-17 2025-09-17
DOMAIN sercontent.com 2025-09-17 2025-09-17
IPv4 45.32.133.19 2025-09-08 2025-09-17

Related Actors

Related Reports

« Back