북한 김수키(Kimsuky)에서 제작한 악성코드-ofx.txt(2025.6.11)

2025-09-16 Sakai Malware Created by North Korean Kimsuky - ofx.txt (2025.6.11)

https://wezard4u.tistory.com/429598

Thumbnail for 북한 김수키(Kimsuky)에서 제작한 악성코드-ofx.txt(2025.6.11)

The excerpt attributes an OFX text-stage script from the “Update Schedule_INVITATION - 250625 UNC Ambassador's Roundtable” archive to Kimsuky activity using a diplomatic-themed lure. The PowerShell collects host profiling data, including the first network adapter IP address, timestamp, last boot time, OS and system details, process listings, and potentially antivirus product information. It writes the collected data under %APPDATA% using an IP-and-time-based filename, Base64-encodes the file, and uploads it to the landjhon/world GitHub repository through the GitHub Contents API. The script uses light string-splitting obfuscation, a hard-coded GitHub personal access token, and deletes the local artifact after upload, showing SaaS-based data exfiltration and cleanup.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.32.133.19 2025-09-08 2025-09-17
HASH 6bb053ca180dcbc3e1d37b2e6ec1cdf1 2025-09-16 2025-09-16
HASH 59ed600b44adc7cb5ac2156e4ff683a… 2025-09-16 2025-09-16
HASH 932f33336632a388c2d2cfb0560c773… 2025-09-16 2025-09-16
DOMAIN ub.com 2025-09-16 2025-09-16

Related Actors

Related Reports

« Back