김수키(Kimsuky) 사례비 지급의서로 위장한 악성코드-231025 (통일부 통일정책실)윤석열 정부의 대북 정책 관련 1.5트랙 전문가 간담회(비공개) 기획안.hwp.lnk(2023.9.14)

2023-09-26 Sakai Kimsuky Malicious code disguised as a letter of compensation payment-231025 (Unification Policy Office, Ministry of Unification) 1.5 track expert meeting (private) related to the North Korea policy of the Yoon Seok-yeol government. Proposal.hwp.lnk (2023.9.14)

https://wezard4u.tistory.com/6608

Thumbnail for 김수키(Kimsuky) 사례비 지급의서로 위장한 악성코드-231025 (통일부 통일정책실)윤석열 정부의 대북 정책 관련 1.5트랙 전문가 간담회(비공개) 기획안.hwp.lnk(2023.9.14)

Kimsuky used a Windows shortcut disguised as a Korean Ministry of Unification policy meeting HWP document to run heavily obfuscated PowerShell from the LNK file. The script carved embedded executable and VBScript data from the shortcut into the user temp path, then contacted isujeil.co.kr under /pg/adm/img/upload1/list.php?query=1. The recovered VBScript used WMI process creation and a hidden scheduled task that repeated every three hours, giving the operators persistence after the lure executed. The source records MD5, SHA1, and SHA256 hashes for the sample, but the main evidence is the LNK to PowerShell and VBScript execution chain.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN dhl.com 2023-09-26 2025-08-29
DOMAIN ystem.io 2023-09-26 2025-08-21
HASH 9fa12b629ca431ebc3aa56da2d7a784a 2023-09-26 2024-01-30
HASH e6d8c130a5d36b968e25659ce10c15e… 2023-09-26 2023-09-26
HASH e1f7cb002b25f60f71d551df45eef5f… 2023-09-26 2023-09-26
URL http://www.isujeil.co.kr/pg/adm… 2023-09-26 2023-09-26

Related Actors

Related Reports

« Back