김수키(Kimsuky)성범죄자의 신상정보공개 양식 으로 위장해서 만든 악성코드-성범죄자 신상정보 고지.pdf.lnk(2025.3.25)
2025-03-28 • Sakai • Kimsuky malware disguised as a sex offender information notice PDF LNK, March 25 2025 •
The report analyzes a Kimsuky-attributed LNK lure named like a sex offender information notice PDF. Execution runs cmd.exe from the shortcut context, changes into the user temporary directory, downloads sfmw.hta from cdn.glitch.global, and launches it with mshta, creating a lightweight script-based infection chain. The report lists hashes for the LNK, including SHA-256 a66c25b1f0dea6e06a4c9f8c5f6ebba0f6c21bd3b9cc326a56702db30418f189, and highlights use of common Windows binaries and writable user paths to reduce friction. Defenders should monitor mshta launches from LNK files, downloads into %TEMP%, and access to the cited Glitch-hosted HTA payload.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a66c25b1f0dea6e06a4c9f8c5f6ebba… | 2025-03-28 | 2025-06-17 |
| DOMAIN | cdn.glitch.global | 2025-03-28 | 2025-05-27 |
| DOMAIN | caller.3utilities.com | 2025-03-28 | 2025-04-10 |
| DOMAIN | blessdayservices.org | 2025-03-28 | 2025-04-10 |
| HASH | 1d64508b384e928046887dd9cb32c2ac | 2025-03-28 | 2025-04-04 |
| HASH | 23cf29e451394d1824046335b2c85ea… | 2025-03-28 | 2025-03-28 |
| URL | https://cdn.glitch.global/2eefa… | 2025-03-28 | 2025-03-28 |