북한 김수키(Kimsuky)에서 만든악성코드-KxS 북한 수해 인터뷰 요청서(대문?아카데미 이?열 이사장님).lnk(2025.4.5)

2025-04-17 Sakai Malware Created by North Korean Kimsuky - KxS North Korea Flood Damage Interview Request (for Chairman Lee X-yeol of Daemun? Academy).lnk (2025.4.5)

http://wezard4u.tistory.com/429459

Thumbnail for 북한 김수키(Kimsuky)에서 만든악성코드-KxS 북한 수해 인터뷰 요청서(대문?아카데미 이?열 이사장님).lnk(2025.4.5)

The Korean malware write-up analyzes an LNK lure named as a North Korea flood interview request and assesses it as likely Kimsuky-related, while explicitly noting the attribution is an estimate. The shortcut masquerades as a PDF and launches hidden PowerShell with execution-policy bypass and a Base64-encoded command. Decoded logic downloads a decoy DOCX and staged PowerShell payloads from Dropboxusercontent URLs, writes scripts such as user.ps1, OperaUpdate.ps1, board_first.ps1, and temp0748634889.ps1 under AppData, executes them, and deletes temporary files. Persistence is created through a hidden scheduled task named OperaUpdate 22-15454342-7.28 that reruns OperaUpdate.ps1 every 30 minutes, giving defenders concrete file paths, task names, hashes, and cloud-delivery patterns to hunt.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 89bca3a895fc2c0b5e975372675f0049 2025-04-17 2025-04-17
HASH 6262c5ef438992966eda78d6d58e631… 2025-04-17 2025-04-17
HASH 169aa69557f591296388c6abe81e6ed… 2025-04-17 2025-04-17
URL https://dl.dropboxusercontent.c… 2025-04-17 2025-04-17
URL https://dl.dropboxusercontent.c… 2025-04-17 2025-04-17

Related Actors

Related Reports

« Back