러시아와 북한 파트너쉽에 관한 논문을 위장한 APT 공격 (Kimsuky)
2024-09-06 • Ahnlab • Kimsuky APT attack disguised as a paper on Russia and North Korea partnership •
AhnLab reports a Kimsuky APT campaign targeting domestic users with decoy Word documents themed around Russia and North Korea relations. The attacker used a GitHub repository to host multiple malicious scripts and benign decoy files, with the scripts ultimately stealing user information. The source also notes Run key persistence and additional file attribute and permission changes to support more refined intrusion activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ac68dad3114c469c5d1e81f9dbc59eb0 | 2024-09-06 | 2024-09-06 |
| HASH | b0e7a8fa1eb5690e7e42fb09c9ee6307 | 2024-09-06 | 2024-09-06 |
| HASH | e5288ab0f625e498e27178b0d17329f9 | 2024-09-06 | 2024-09-06 |
Related Actors
Related Reports
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
Shares tag: Kimsuky • Same author: Ahnlab
Shares tag: Kimsuky • Same author: Ahnlab
Shares tag: Kimsuky • Same author: Ahnlab
Shares tag: Kimsuky • Same author: Ahnlab
Shares tag: Kimsuky • Published within a month