김수키(Kimsuky)에서 만든 보험 사칭 악성코드-241002-2024년 GA영업본부 담당지점 배분(10월)(2025.1.31)
2025-02-04 • Sakai • Insurance-Impersonating Malware Created by Kimsuky - 241002-2024 GA Sales Headquarters Branch Allocation (October) (2025.1.31) •
A Kimsuky-attributed lure used a Korean insurance-themed Windows shortcut named as a PDF for a 2024 GA sales-branch allocation document. The LNK executed Base64-decoded PowerShell that downloaded and opened a decoy PDF from Dropbox, then wrote chrome.ps1 under AppData for follow-on execution. Persistence was established through a hidden scheduled task named ChromeUpdateTaskMachine that ran PowerShell with ExecutionPolicy Bypass five minutes later and repeated every 30 minutes. The script also downloaded additional PowerShell payloads such as temp.ps1 and system_first.ps1 from Dropbox, executed them, and removed files afterward, giving defenders concrete LNK, PowerShell, Dropbox, AppData, and scheduled-task artifacts to hunt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 71d56c61b765eee74dca65910ab9e0e… | 2025-02-04 | 2025-02-13 |
| HASH | 8a08fd5e8298c823e4ab356508d70490 | 2025-02-04 | 2025-02-04 |
| HASH | 086be54505ef95d83be71d6b1e95961… | 2025-02-04 | 2025-02-04 |
| URL | https://dl.dropboxusercontent.c… | 2025-02-04 | 2025-02-04 |
| URL | https://dl.dropboxusercontent.c… | 2025-02-04 | 2025-02-04 |
| URL | https://dl.dropboxusercontent.c… | 2025-02-04 | 2025-02-04 |
| URL | https://dl.dropboxusercontent.c… | 2025-02-04 | 2025-02-04 |
| URL | https://dl.dropboxusercontent.c… | 2025-02-04 | 2025-02-04 |