북한 김수키(Kimsuky) CJ올리브네트웍스 인증서 악용한 기계연 공격 악성코드-20250428 플x아이 작업계획서 및 작업완료서_기계연 이X화.scr(2025.5.7)
2025-05-19 • Sakai • North Korean Kimsuky Malware Abusing a CJ OliveNetworks Certificate to Attack KIMM - 20250428 Plan and Completion Report for KIMM Lee X-hwa.scr (2025.5.7) •
Kimsuky is tied to an attack using a malicious SCR file disguised as Korean machinery-research work-plan and completion documents. The sample reportedly carried a CJ OliveNetworks digital signature issued by Sectigo, which CJ OliveNetworks revoked after the abuse was identified. The excerpt lists hashes for the SCR and a downloaded payload, then describes config.dat code with heavy obfuscation, conditional memory manipulation, self-modifying behavior, dynamic function-pointer execution, and anti-debug or anti-emulation style control flow. Reported infrastructure includes a login.php URL on a Korean free-domain service resolving to 162.220.11.186, highlighting continued DPRK-linked abuse of trusted certificates, document lures, and evasive payload staging against South Korean targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://gsegse.dasfesfgsegsefsed… | 2025-05-19 | 2026-04-07 |
| DOMAIN | gsegse.dasfesfgsegsefsede.o-r.kr | 2025-05-15 | 2026-04-07 |
| HASH | 7ec88818697623a0130b1de42fa31335 | 2025-05-15 | 2025-05-30 |
| HASH | 580d7a5fdf78dd3e720b2ce772dc77e9 | 2025-05-15 | 2025-05-30 |
| HASH | 49fd125c5f516be6883404c256d79af… | 2025-05-19 | 2025-05-19 |
| HASH | 123aefe0734da130b475bfdad6c3ebe… | 2025-05-19 | 2025-05-19 |
| HASH | df3e07199e8457341dd06dfa5b04d6a… | 2025-05-19 | 2025-05-19 |
| HASH | 7047efbd15b20086933a3e41f23252d… | 2025-05-19 | 2025-05-19 |
| IPv4 | 162.220.11.186 | 2025-05-19 | 2025-05-19 |