북한 김수키(Kimsuky)에서 만든 악성코드-미신고 자금 출처명세서(찾아가는 법 찾기).zip(2025.6.4)

2025-06-23 Sakai Malware Created by North Korean Kimsuky - Unreported Source of Funds Statement (How to Find Visiting Legal Services).zip (2025.6.4)

https://wezard4u.tistory.com/429517

Thumbnail for 북한 김수키(Kimsuky)에서 만든 악성코드-미신고 자금 출처명세서(찾아가는 법 찾기).zip(2025.6.4)

The Korean write-up attributes a tax-themed malware lure to Kimsuky and assesses that it was likely intended for email delivery to victims. The archive contained decoy HWP tax documents and a key HWP-themed LNK file that ran obfuscated PowerShell, searched for a marker-sized shortcut, decoded embedded bytes with XOR, executed the extracted payload, and removed the shortcut artifact. The follow-on command copied curl.exe and schtasks.exe into C:\Users\Public\Videos under renamed filenames, downloaded AutoIt3.exe and a CDR payload from thegreatratings[.]com, and created a scheduled task named CfjiFUW to run every minute. The lure abused South Korean tax and undeclared-funds documentation themes, making it relevant to DPRK tracking of Kimsuky social engineering against Korean-language targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b24b1aa0a95e1c1a594bd8b34877fa1… 2025-06-23 2025-06-23
HASH f1aa607507e97cf2dee3d3059d3b2b1… 2025-06-23 2025-06-23
HASH 31bd1480d76972b1727c9ef6953741f… 2025-06-23 2025-06-23
HASH 2d516c97e510bbdfb89eae329b88e0b… 2025-06-23 2025-06-23
HASH cc72c5bf20e8d5d6efa66dfc1d8efaa4 2025-06-23 2025-06-23
HASH e2328974ecc81be06619bbd06ebfacb4 2025-06-23 2025-06-23
URL https://thegreatratings.com/wp-… 2025-06-23 2025-06-23
DOMAIN ngs.com 2025-06-23 2025-06-23
DOMAIN thegreatratings.com 2025-06-23 2025-06-23
IPv4 66.96.162.245 2025-06-23 2025-06-23

Related Actors

Related Reports

« Back