북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-자금출처명세서(2025.5.26)

2025-08-04 Sakai Malware made by North Korean hacking group Kimsuky: statement of source of funds

https://wezard4u.tistory.com/429558

Thumbnail for 북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-자금출처명세서(2025.5.26)

The analysis attributes a malicious LNK file disguised as an HWP document to Kimsuky and shows it abusing PowerShell to locate a specific-size shortcut file and extract embedded data. The script reads bytes from offset 0x17DC, XOR-decrypts them with 0x8C, writes the result as an executable, runs it, and removes the original shortcut. It then copies curl.exe and schtasks.exe under new names, downloads AutoIt3.exe and a .cdr payload from customelisa.com, and creates a scheduled task that runs every minute for persistence. The excerpt says the malware was distributed through a compromised WordPress site, making the case relevant to South Korea-focused DPRK intrusion tracking and website-abuse monitoring.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 545a059e5bc1ac9cc679c90d92454b5… 2025-08-04 2025-08-04
HASH fa529dd599e6d20dab3ffc95900e35cf 2025-08-04 2025-08-04
HASH 0b59408934d95418f0b82ea6ee408a9… 2025-08-04 2025-08-04
URL https://customelisa.com/js/hurr… 2025-08-04 2025-08-04
URL https://customelisa.com/js/hurr… 2025-08-04 2025-08-04
URL https://customelisa.com/js/hurr… 2025-08-04 2025-08-04
URL https://customelisa.com/js/hurr… 2025-08-04 2025-08-04
DOMAIN customelisa.com 2025-08-04 2025-08-04

Related Actors

Related Reports

« Back