북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-근로신청서 관련의 건.docx.lnk(2024.7.9)
2024-07-17 • Sakai • Kimsuky malware disguised as an employment application document shortcut •
The Korean source attributes a malicious Windows shortcut disguised as an employment application document to Kimsuky. The LNK launches obfuscated PowerShell with execution-policy bypass, decodes embedded Base64 script content, searches for matching shortcut files, and extracts additional data from the LNK. Execution creates VBS and temporary files under ProgramData, runs them with wscript.exe, and uses Dropbox API upload and download endpoints for network activity. The report provides hashes for the lure and notes antivirus detections for the LNK dropper.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://content.dropboxapi.com/… | 2020-03-25 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2018-09-21 | 2025-09-03 |
| HASH | 21d12dc7f08752293847af6ed19df0e3 | 2024-07-17 | 2024-09-05 |
| HASH | 5074647737b8b996b597c1719b571cc… | 2024-07-17 | 2024-07-17 |
| HASH | e7e73a5133cd61c077f85c44e9efeb8… | 2024-07-17 | 2024-07-17 |
Related Actors
Related Reports
Shares tags: Kimsuky, LNK • Same author: Sakai • Published within a month
Shares tags: Kimsuky, LNK • Shares 1 IOC • Same author: Sakai
Shares tags: Kimsuky, LNK • Shares 1 IOC • Same author: Sakai
Shares tags: Kimsuky, LNK • Same author: Sakai
Shares tags: Kimsuky, LNK • Same author: Sakai
Shares tags: Kimsuky, LNK • Same author: Sakai