로그인 정보를 훔치는것 으로 추정 되는 북한 APT 김수키(Kimsuky)만든 악성코드-.lnk(2024.11.8)

2024-11-13 Sakai Malware Presumed to Steal Login Information, Created by North Korea's APT Kimsuky - .lnk (2024.11.8)

https://wezard4u.tistory.com/429328

Thumbnail for 로그인 정보를 훔치는것 으로 추정 되는 북한 APT 김수키(Kimsuky)만든 악성코드-.lnk(2024.11.8)

A Korean malware write-up analyzes a Windows LNK sample attributed to Kimsuky and assessed as likely designed to steal login information. The evidence includes file hashes for the shortcut, obfuscated command-line content embedded in the LNK, and Windows shortcut metadata rather than a benign document workflow. Defenders should treat the sample as DPRK-linked credential-theft activity, pivot on the published MD5, SHA-1, and SHA-256 values, and monitor for suspicious shortcut execution chains that launch command interpreters or scripted payloads.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://partybbq.co.kr/src/bbs/… 2024-11-13 2024-11-13
HASH e13ad0ebaac36ec363eba5760e69cb9… 2024-11-08 2024-11-13
HASH b7de564386ab778046b1dd3ef76e4b5e 2024-11-08 2024-11-13
HASH baa69876baa6861db5736c58d2eded9… 2024-11-08 2024-11-13
URL http://partybbq.co.kr/src/bbs/c… 2023-08-28 2024-11-13
DOMAIN partybbq.co.kr 2023-05-24 2024-11-13

Related Actors

Related Reports

« Back