김수키(Kimsuky)워드 악성코드-협의 이혼 의사 확인 신청서.doc(2023.06.28)
2023-06-30 • Sakai • Kimsuky word malware - application for confirmation of intention to divorce by agreement.doc (2023.06.28) •
Wezard4u analyzed a Kimsuky-themed malicious Word document disguised as a Korean divorce-related form. The Korean post says the document uses an AutoOpen VBA macro to write and execute a VBScript under the user’s Microsoft Templates directory, which downloads and executes additional code from a Google Drive URL. The sample is tracked with hashes including SHA-256 ea451e5c064f79f66433d2311e90b965d1ee26cabc411f633d826cdb6920b83e and was detected by multiple antivirus engines as macro/downloader malware. The author frames the activity as likely tied to a North Korea-linked reconnaissance group and notes Kimsuky’s broader targeting of South Korean think tanks, industry, nuclear-sector, defector, military, diplomatic, and government-related communities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 716b5e039177f7f6d50404bde0be9e4b | 2023-06-30 | 2023-06-30 |
| HASH | b4635d3d6adbe3c0674032db712e26c… | 2023-06-30 | 2023-06-30 |
| HASH | ea451e5c064f79f66433d2311e90b96… | 2023-06-30 | 2023-06-30 |