김수키(Kimsuky)에서 만든 보험 사칭 악성코드-241002-2024년 GA영업본부 담당지점 배분(10월)(2025.1.31)

2025-02-04 Sakai Insurance-Impersonating Malware Created by Kimsuky - 241002-2024 GA Sales Headquarters Branch Allocation (October) (2025.1.31)

https://wezard4u.tistory.com/429397

Thumbnail for 김수키(Kimsuky)에서 만든 보험 사칭 악성코드-241002-2024년 GA영업본부 담당지점 배분(10월)(2025.1.31)

A Kimsuky-attributed lure used a Korean insurance-themed Windows shortcut named as a PDF for a 2024 GA sales-branch allocation document. The LNK executed Base64-decoded PowerShell that downloaded and opened a decoy PDF from Dropbox, then wrote chrome.ps1 under AppData for follow-on execution. Persistence was established through a hidden scheduled task named ChromeUpdateTaskMachine that ran PowerShell with ExecutionPolicy Bypass five minutes later and repeated every 30 minutes. The script also downloaded additional PowerShell payloads such as temp.ps1 and system_first.ps1 from Dropbox, executed them, and removed files afterward, giving defenders concrete LNK, PowerShell, Dropbox, AppData, and scheduled-task artifacts to hunt.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 71d56c61b765eee74dca65910ab9e0e… 2025-02-04 2025-02-13
HASH 8a08fd5e8298c823e4ab356508d70490 2025-02-04 2025-02-04
HASH 086be54505ef95d83be71d6b1e95961… 2025-02-04 2025-02-04
URL https://dl.dropboxusercontent.c… 2025-02-04 2025-02-04
URL https://dl.dropboxusercontent.c… 2025-02-04 2025-02-04
URL https://dl.dropboxusercontent.c… 2025-02-04 2025-02-04
URL https://dl.dropboxusercontent.c… 2025-02-04 2025-02-04
URL https://dl.dropboxusercontent.c… 2025-02-04 2025-02-04

Related Actors

Related Reports

« Back