김수키(Kimsuky) 에서 만든 악성코드-2025-03-05임x철대표님께드리는글.pdf.lnk(2025.3.6)
2025-03-10 • Sakai • Kimsuky Malware Disguised as a PDF Addressed to a Company Executive •
A Kimsuky-linked LNK file masquerades as a Korean PDF addressed to an executive associated with Blocore and Gameberry, suggesting targeting of technology-sector leadership. The shortcut contains AES-encrypted data and embedded PowerShell that decrypts a script, writes home.ps1 in the temporary directory, and runs it hidden with ExecutionPolicy Bypass. The decrypted script downloads a decoy PDF from a compromised koreaauditor.org path, contacts tony.php endpoints, retrieves error_log.ps1 into Public Documents, and creates a hidden VBS launcher. Persistence is established through a scheduled task named MicrosoftEdgeUpdateTaskCleaner that runs cscript.exe every 30 minutes, making the lure and infrastructure useful indicators for DPRK-focused intrusion tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8cd66575b9d4f6688fff9cc1e238a84… | 2025-03-10 | 2025-03-10 |
| HASH | f2a9c827539183178e9175be36995de0 | 2025-03-10 | 2025-03-10 |
| HASH | ff77862dd29e51dcb88242e965d3ed0… | 2025-03-10 | 2025-03-10 |
| URL | https://koreaauditor.org/data/m… | 2025-03-10 | 2025-03-10 |
| DOMAIN | koreaauditor.org | 2025-03-10 | 2025-03-10 |