북한 해킹단체 김수키(Kimsuky)에서 만든 악성코드-SecurityMail.chm(2025.3.31)

2025-06-05 Sakai Malware Created by North Korean Hacking Group Kimsuky - SecurityMail.chm (2025.3.31)

http://wezard4u.tistory.com/429504

Thumbnail for 북한 해킹단체 김수키(Kimsuky)에서 만든 악성코드-SecurityMail.chm(2025.3.31)

A Kimsuky-linked CHM file named SecurityMail.chm presents a Korean virtual-asset user-protection notice as a decoy while hiding malicious execution logic inside the compiled HTML help content. The embedded HTML abuses an ActiveX object to launch hidden PowerShell, writes a Base64 payload into the user's Links directory, decodes it with certutil, and runs the resulting script with wscript. The decoded script creates a Microsoft.XMLHTTP object, requests commands from noreplymail[.]space under the BitJoker path with a randomized tag parameter, and executes the server response, enabling remote code execution and follow-on command delivery. The lure content and the author's assessment point to possible cryptocurrency-related targeting, while the infrastructure note links the domain to 46.202.158[.]9 and prior Konni-associated URL usage.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7047878f4fbea323148f6554afe6169… 2025-06-05 2026-04-17
HASH a76af8176da28fdab47f9a77d50eb0e… 2025-06-05 2026-04-17
HASH 4599ac1bbe483c73064df1353feafd01 2025-06-05 2026-04-17
DOMAIN noreplymail.space 2025-06-05 2026-04-17
URL http://noreplymail.space/BitJok… 2025-06-05 2025-06-05
URL http://noreplymail.space/BitJ 2025-06-05 2025-06-05
IPv4 46.202.158.9 2025-06-05 2025-06-05

Related Actors

Related Reports

« Back