김수키(Kimsuky) 추정 국방대학교 안보정책학부 교수를 노린 주한 중화인민공화국 대사관 무관부 사칭 악성코드
2025-09-24 • Sakai • Kimsuky-themed malware analysis report •
A Korean-language analysis attributes a malicious LNK lure to suspected Kimsuky activity targeting a Korea National Defense University security policy professor. The lure impersonated the Military Affairs Office of the Chinese Embassy in South Korea and dropped a decoy HWP invitation for a Chinese National Day reception while running hidden PowerShell. The script extracted an embedded HWP, deleted the original LNK, used Base64 and string-splitting obfuscation, attempted to kill archive or analysis tools such as Bandizip, WinRAR, and 7zFM, and fetched a remote script from raw.githubusercontent.com under the aeufff repositories. The activity matters because it combines a defense-policy academic target, plausible diplomatic event content, GitHub-hosted payload retrieval, and anti-analysis behavior consistent with targeted espionage tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 25f648c7d0d4867bd3635cbb8099582… | 2025-09-24 | 2025-09-24 |
| HASH | 74e10df9726c953692fefc468b724c7… | 2025-09-24 | 2025-09-24 |
| HASH | 55fc6e5127e9409d10f57f7e5abca50b | 2025-09-24 | 2025-09-24 |