김수키(Kimsuky)성범죄자의 신상정보공개 양식 으로 위장해서 만든 악성코드-성범죄자 신상정보 고지.pdf.lnk(2025.3.25)

2025-03-28 Sakai Kimsuky malware disguised as a sex offender information notice PDF LNK, March 25 2025

https://wezard4u.tistory.com/429442

Thumbnail for 김수키(Kimsuky)성범죄자의 신상정보공개 양식 으로 위장해서 만든 악성코드-성범죄자 신상정보 고지.pdf.lnk(2025.3.25)

The report analyzes a Kimsuky-attributed LNK lure named like a sex offender information notice PDF. Execution runs cmd.exe from the shortcut context, changes into the user temporary directory, downloads sfmw.hta from cdn.glitch.global, and launches it with mshta, creating a lightweight script-based infection chain. The report lists hashes for the LNK, including SHA-256 a66c25b1f0dea6e06a4c9f8c5f6ebba0f6c21bd3b9cc326a56702db30418f189, and highlights use of common Windows binaries and writable user paths to reduce friction. Defenders should monitor mshta launches from LNK files, downloads into %TEMP%, and access to the cited Glitch-hosted HTA payload.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a66c25b1f0dea6e06a4c9f8c5f6ebba… 2025-03-28 2025-06-17
DOMAIN cdn.glitch.global 2025-03-28 2025-05-27
DOMAIN caller.3utilities.com 2025-03-28 2025-04-10
DOMAIN blessdayservices.org 2025-03-28 2025-04-10
HASH 1d64508b384e928046887dd9cb32c2ac 2025-03-28 2025-04-04
HASH 23cf29e451394d1824046335b2c85ea… 2025-03-28 2025-03-28
URL https://cdn.glitch.global/2eefa… 2025-03-28 2025-03-28

Related Actors

Related Reports

« Back