김수키(Kimsuky) 추정 국방대학교 안보정책학부 교수를 노린 주한 중화인민공화국 대사관 무관부 사칭 악성코드

2025-09-24 Sakai Kimsuky-themed malware analysis report

https://wezard4u.tistory.com/429603

Thumbnail for 김수키(Kimsuky) 추정 국방대학교 안보정책학부 교수를 노린 주한 중화인민공화국 대사관 무관부 사칭 악성코드

A Korean-language analysis attributes a malicious LNK lure to suspected Kimsuky activity targeting a Korea National Defense University security policy professor. The lure impersonated the Military Affairs Office of the Chinese Embassy in South Korea and dropped a decoy HWP invitation for a Chinese National Day reception while running hidden PowerShell. The script extracted an embedded HWP, deleted the original LNK, used Base64 and string-splitting obfuscation, attempted to kill archive or analysis tools such as Bandizip, WinRAR, and 7zFM, and fetched a remote script from raw.githubusercontent.com under the aeufff repositories. The activity matters because it combines a defense-policy academic target, plausible diplomatic event content, GitHub-hosted payload retrieval, and anti-analysis behavior consistent with targeted espionage tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 25f648c7d0d4867bd3635cbb8099582… 2025-09-24 2025-09-24
HASH 74e10df9726c953692fefc468b724c7… 2025-09-24 2025-09-24
HASH 55fc6e5127e9409d10f57f7e5abca50b 2025-09-24 2025-09-24

Related Actors

Related Reports

« Back