김수키(Kimsuky) 조직 여권 위장 공격:개인정보 탈취를 위한 악성코드 분석(2025.6.18)
2025-07-01 • Sakai • Kimsuky Passport-Themed Attack: Analysis of Malware for Stealing Personal Information (2025.6.18) •
A Korean analysis links a passport-themed malware case to Kimsuky and suggests that Korean passport imagery may have been stolen or otherwise abused as lure material. The sample is identified by MD5, SHA-1, and SHA-256 hashes, with embedded payloads encoded three times in Base64 before dropping chromeupdate.js under %APPDATA%\Microsoft\Windows\Templates. Persistence is created through a scheduled task named "Google Chrome Update" that runs wscript.exe every minute, while PowerShell and WebClient activity sends the victim computer name and OS version to attacker-controlled PHP endpoints. The chain downloads a decoy Template.pdf and executes additional code from nidnaver.cloud infrastructure, making the case relevant for tracking Kimsuky use of personal-document lures and lightweight script-based persistence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3480dd059adb53a6be9d063d16f6f22… | 2025-07-01 | 2025-07-01 |
| HASH | 0e75a7d2077c13eb5c8b1329ea3b254… | 2025-07-01 | 2025-07-01 |
| HASH | c0b47dc97cf9552b564cb227b6de12c3 | 2025-07-01 | 2025-07-01 |
| URL | http://knees.nidnaver.cloud/fre… | 2025-07-01 | 2025-07-01 |
| URL | http://toes.nidnaver.cloud/free… | 2025-07-01 | 2025-07-01 |
| URL | http://toes.nidnaver.cloud/free… | 2025-07-01 | 2025-07-01 |
| DOMAIN | toes.nidnaver.cloud | 2025-07-01 | 2025-07-01 |