북한 김수키(Kimsuky)에서 만든악성코드-KxS 북한 수해 인터뷰 요청서(대문?아카데미 이?열 이사장님).lnk(2025.4.5)
2025-04-17 • Sakai • Malware Created by North Korean Kimsuky - KxS North Korea Flood Damage Interview Request (for Chairman Lee X-yeol of Daemun? Academy).lnk (2025.4.5) •
The Korean malware write-up analyzes an LNK lure named as a North Korea flood interview request and assesses it as likely Kimsuky-related, while explicitly noting the attribution is an estimate. The shortcut masquerades as a PDF and launches hidden PowerShell with execution-policy bypass and a Base64-encoded command. Decoded logic downloads a decoy DOCX and staged PowerShell payloads from Dropboxusercontent URLs, writes scripts such as user.ps1, OperaUpdate.ps1, board_first.ps1, and temp0748634889.ps1 under AppData, executes them, and deletes temporary files. Persistence is created through a hidden scheduled task named OperaUpdate 22-15454342-7.28 that reruns OperaUpdate.ps1 every 30 minutes, giving defenders concrete file paths, task names, hashes, and cloud-delivery patterns to hunt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 89bca3a895fc2c0b5e975372675f0049 | 2025-04-17 | 2025-04-17 |
| HASH | 6262c5ef438992966eda78d6d58e631… | 2025-04-17 | 2025-04-17 |
| HASH | 169aa69557f591296388c6abe81e6ed… | 2025-04-17 | 2025-04-17 |
| URL | https://dl.dropboxusercontent.c… | 2025-04-17 | 2025-04-17 |
| URL | https://dl.dropboxusercontent.c… | 2025-04-17 | 2025-04-17 |