김수키(Kimsuky) 조직 여권 위장 공격:개인정보 탈취를 위한 악성코드 분석(2025.6.18)

2025-07-01 Sakai Kimsuky Passport-Themed Attack: Analysis of Malware for Stealing Personal Information (2025.6.18)

https://wezard4u.tistory.com/429525

Thumbnail for 김수키(Kimsuky) 조직 여권 위장 공격:개인정보 탈취를 위한 악성코드 분석(2025.6.18)

A Korean analysis links a passport-themed malware case to Kimsuky and suggests that Korean passport imagery may have been stolen or otherwise abused as lure material. The sample is identified by MD5, SHA-1, and SHA-256 hashes, with embedded payloads encoded three times in Base64 before dropping chromeupdate.js under %APPDATA%\Microsoft\Windows\Templates. Persistence is created through a scheduled task named "Google Chrome Update" that runs wscript.exe every minute, while PowerShell and WebClient activity sends the victim computer name and OS version to attacker-controlled PHP endpoints. The chain downloads a decoy Template.pdf and executes additional code from nidnaver.cloud infrastructure, making the case relevant for tracking Kimsuky use of personal-document lures and lightweight script-based persistence.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3480dd059adb53a6be9d063d16f6f22… 2025-07-01 2025-07-01
HASH 0e75a7d2077c13eb5c8b1329ea3b254… 2025-07-01 2025-07-01
HASH c0b47dc97cf9552b564cb227b6de12c3 2025-07-01 2025-07-01
URL http://knees.nidnaver.cloud/fre… 2025-07-01 2025-07-01
URL http://toes.nidnaver.cloud/free… 2025-07-01 2025-07-01
URL http://toes.nidnaver.cloud/free… 2025-07-01 2025-07-01
DOMAIN toes.nidnaver.cloud 2025-07-01 2025-07-01

Related Actors

Related Reports

« Back