북한 김수키(Kimsuky)에서 만든 국세청 사칭 악성코드-22 귀속 부가가치세 면세사업자 사업장 현황신고(2023.4.6)
2023-05-05 • Sakai • Malicious code impersonating the National Tax Service created by Kimsuky in North Korea-22 Report on business status for value-added tax exempt businesses (April 6, 2023) •
The Korean analysis describes a Kimsuky-attributed campaign using a RAR archive themed as a South Korean National Tax Service notice for VAT-exempt business status reporting. Inside the archive, a very large LNK file masquerading as an HWP tax-audit notice launches hidden PowerShell that decodes embedded hexadecimal script content, extracts payload data from the oversized shortcut, writes files into public/documents paths, and starts a VBS script. The source provides hashes for the archive and LNK and places the activity in Kimsuky’s broader espionage targeting of South Korean policy, defense, diplomacy, defector, and related organizations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | resolver1.opendns.com | 2023-05-05 | 2023-12-18 |
| HASH | c0ac380c3dcf94eef84e40ef964a662… | 2023-05-05 | 2023-11-24 |
| URL | http://centhosting.net/upload.p… | 2023-05-05 | 2023-11-24 |
| URL | http://centhosting.net/list.php… | 2023-05-05 | 2023-11-24 |
| DOMAIN | centhosting.net | 2023-05-05 | 2023-11-24 |
| HASH | 58d726099fdd9fdb8c34e96e13473aa4 | 2023-05-05 | 2023-05-18 |
| HASH | 2b2310574eb43608eec2540782e08b35 | 2023-05-05 | 2023-05-18 |
| HASH | 17718cc9534c10fa30f3ec3d16407e3… | 2023-05-05 | 2023-05-05 |
| HASH | 274792046756c6c4e616d653b7d3b24… | 2023-05-05 | 2023-05-05 |
| HASH | b20275c27202b202730353733342e7a6 | 2023-05-05 | 2023-05-05 |
| HASH | 1b415bcc45cfb06c1a649b0a379daae… | 2023-05-05 | 2023-05-05 |
| HASH | 027646f63756d656e747327292e436f7 | 2023-05-05 | 2023-05-05 |
| HASH | 871464a6b762b3d5b636861725d2824… | 2023-05-05 | 2023-05-05 |
| HASH | fbe8954a7495380b1f905eb729589f8… | 2023-05-05 | 2023-05-05 |