북한 해킹단체 김수키(Kimsuky)에서 만든 악성코드-SecurityMail.chm(2025.3.31)
2025-06-05 • Sakai • Malware Created by North Korean Hacking Group Kimsuky - SecurityMail.chm (2025.3.31) •
A Kimsuky-linked CHM file named SecurityMail.chm presents a Korean virtual-asset user-protection notice as a decoy while hiding malicious execution logic inside the compiled HTML help content. The embedded HTML abuses an ActiveX object to launch hidden PowerShell, writes a Base64 payload into the user's Links directory, decodes it with certutil, and runs the resulting script with wscript. The decoded script creates a Microsoft.XMLHTTP object, requests commands from noreplymail[.]space under the BitJoker path with a randomized tag parameter, and executes the server response, enabling remote code execution and follow-on command delivery. The lure content and the author's assessment point to possible cryptocurrency-related targeting, while the infrastructure note links the domain to 46.202.158[.]9 and prior Konni-associated URL usage.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7047878f4fbea323148f6554afe6169… | 2025-06-05 | 2026-04-17 |
| HASH | a76af8176da28fdab47f9a77d50eb0e… | 2025-06-05 | 2026-04-17 |
| HASH | 4599ac1bbe483c73064df1353feafd01 | 2025-06-05 | 2026-04-17 |
| DOMAIN | noreplymail.space | 2025-06-05 | 2026-04-17 |
| URL | http://noreplymail.space/BitJok… | 2025-06-05 | 2025-06-05 |
| URL | http://noreplymail.space/BitJ | 2025-06-05 | 2025-06-05 |
| IPv4 | 46.202.158.9 | 2025-06-05 | 2025-06-05 |