북한 김수키(Kimsuky) CJ올리브네트웍스 인증서 악용한 기계연 공격 악성코드-20250428 플x아이 작업계획서 및 작업완료서_기계연 이X화.scr(2025.5.7)

2025-05-19 Sakai North Korean Kimsuky Malware Abusing a CJ OliveNetworks Certificate to Attack KIMM - 20250428 Plan and Completion Report for KIMM Lee X-hwa.scr (2025.5.7)

http://wezard4u.tistory.com/429487

Thumbnail for 북한 김수키(Kimsuky) CJ올리브네트웍스 인증서 악용한 기계연 공격 악성코드-20250428 플x아이 작업계획서 및 작업완료서_기계연 이X화.scr(2025.5.7)

Kimsuky is tied to an attack using a malicious SCR file disguised as Korean machinery-research work-plan and completion documents. The sample reportedly carried a CJ OliveNetworks digital signature issued by Sectigo, which CJ OliveNetworks revoked after the abuse was identified. The excerpt lists hashes for the SCR and a downloaded payload, then describes config.dat code with heavy obfuscation, conditional memory manipulation, self-modifying behavior, dynamic function-pointer execution, and anti-debug or anti-emulation style control flow. Reported infrastructure includes a login.php URL on a Korean free-domain service resolving to 162.220.11.186, highlighting continued DPRK-linked abuse of trusted certificates, document lures, and evasive payload staging against South Korean targets.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://gsegse.dasfesfgsegsefsed… 2025-05-19 2026-04-07
DOMAIN gsegse.dasfesfgsegsefsede.o-r.kr 2025-05-15 2026-04-07
HASH 7ec88818697623a0130b1de42fa31335 2025-05-15 2025-05-30
HASH 580d7a5fdf78dd3e720b2ce772dc77e9 2025-05-15 2025-05-30
HASH 49fd125c5f516be6883404c256d79af… 2025-05-19 2025-05-19
HASH 123aefe0734da130b475bfdad6c3ebe… 2025-05-19 2025-05-19
HASH df3e07199e8457341dd06dfa5b04d6a… 2025-05-19 2025-05-19
HASH 7047efbd15b20086933a3e41f23252d… 2025-05-19 2025-05-19
IPv4 162.220.11.186 2025-05-19 2025-05-19

Related Actors

Related Reports

« Back