‘보안 메일’도 안심 금물! 카드사 사칭 악성 파일 유포 중

2026-05-27 Ahnlab Even ‘Secure Mail’ Is Not Safe: Malicious Files Impersonating a Card Company Are Being Distributed

https://asec.ahnlab.com/ko/93854/

Thumbnail for ‘보안 메일’도 안심 금물! 카드사 사칭 악성 파일 유포 중

AhnLab observed malicious LNK files distributed as secure email from a well-known Korean card company, with a flow similar to earlier Kimsuky password-file lure activity but with changed initial commands. The LNK launches PowerShell and `mshta` to run an HTA containing obfuscated VBScript, drops a decoy document, and then changes its follow-on behavior depending on whether Windows Defender is running. In Defender-enabled environments it downloads and decrypts `pipe.log` into `pipe.zip`, which contains components for backdoor activity, information theft, keylogging, and clipboard collection. When Defender is stopped, it downloads `user.txt` and `sys.log`, decrypts and loads `sys.dll` with `rundll32`, avoids VirtualBox and VMware, and retrieves additional payloads from Google Drive. The payload set includes remote command execution, file transfer, host and browser data collection, MeshAgent configuration retrieval, Chrome process injection for cookie theft, and theft of browser and email-client credentials.

Related Actors

Related Reports

2026-04-17 • 54% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing, T1140
« Back