김수키(Kimsuky) 서울대 국제문제연구소 사칭 악성코드-글로벌 복합 위기 한국의 안보전략.lnk(2025.9.28)

2025-10-03 Sakai Kimsuky-themed malware analysis report

https://wezard4u.tistory.com/429610

Thumbnail for 김수키(Kimsuky) 서울대 국제문제연구소 사칭 악성코드-글로벌 복합 위기 한국의 안보전략.lnk(2025.9.28)

A Kimsuky-linked LNK malware sample used a lure titled “Global Complex Crisis, Korea’s Security Strategy” and presented an HWP document tied to a Seoul National University security-strategy event. The shortcut launches hidden PowerShell, searches for a 56,397-byte LNK file, extracts an embedded 50,688-byte HWP payload from offset 5709, writes and opens it, then deletes the original shortcut. The script also decodes a base64 string and repeatedly executes it with Invoke-Expression, enabling follow-on download, command execution, or C2 behavior as described by the source. Reported indicators include the LNK filename, file size, MD5, SHA-1, SHA-256, and an icon URL hosted on raw.githubusercontent.com. The activity is relevant because it shows Kimsuky continuing to use Korea-focused policy and academic themes with LNK-to-PowerShell execution chains.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 26bf7746400d81c4fa11b29a2abac4c… 2025-10-03 2025-10-03
HASH cb7fc4243f70956ea8c2ba961d4a4b3… 2025-10-03 2025-10-03
HASH dea5ea1f43819570b82c95ff2cfef3b4 2025-10-03 2025-10-03

Related Actors

Related Reports

« Back