김수키(Kimsuky) 에서 만든 악성코드-2025-03-05임x철대표님께드리는글.pdf.lnk(2025.3.6)

2025-03-10 Sakai Kimsuky Malware Disguised as a PDF Addressed to a Company Executive

https://wezard4u.tistory.com/429426

Thumbnail for 김수키(Kimsuky) 에서 만든 악성코드-2025-03-05임x철대표님께드리는글.pdf.lnk(2025.3.6)

A Kimsuky-linked LNK file masquerades as a Korean PDF addressed to an executive associated with Blocore and Gameberry, suggesting targeting of technology-sector leadership. The shortcut contains AES-encrypted data and embedded PowerShell that decrypts a script, writes home.ps1 in the temporary directory, and runs it hidden with ExecutionPolicy Bypass. The decrypted script downloads a decoy PDF from a compromised koreaauditor.org path, contacts tony.php endpoints, retrieves error_log.ps1 into Public Documents, and creates a hidden VBS launcher. Persistence is established through a scheduled task named MicrosoftEdgeUpdateTaskCleaner that runs cscript.exe every 30 minutes, making the lure and infrastructure useful indicators for DPRK-focused intrusion tracking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8cd66575b9d4f6688fff9cc1e238a84… 2025-03-10 2025-03-10
HASH f2a9c827539183178e9175be36995de0 2025-03-10 2025-03-10
HASH ff77862dd29e51dcb88242e965d3ed0… 2025-03-10 2025-03-10
URL https://koreaauditor.org/data/m… 2025-03-10 2025-03-10
DOMAIN koreaauditor.org 2025-03-10 2025-03-10

Related Actors

Related Reports

« Back