북한 해킹 단체 김수키(Kimsuky)에서 만든 PowerShell 백도어 도구(2024.2.29)

2024-08-01 Sakai PowerShell Backdoor Tool Created by the North Korean Hacking Group Kimsuky (2024.2.29)

https://wezard4u.tistory.com/429244

Thumbnail for 북한 해킹 단체 김수키(Kimsuky)에서 만든 PowerShell 백도어 도구(2024.2.29)

The excerpt analyzes a Kimsuky-attributed PowerShell backdoor that repeatedly connects to a server, sleeps between attempts, and continues until the server instructs it to close. The script generates a victim identifier from the host's MAC and IPv4 address, prepares RC4 send and receive keys, and sends an initial unique-ID packet over a TCP socket. Its RemoteFileManager functionality defines commands for drive and path listing, file download and upload, deletion, renaming, directory creation, execution, restart, removal, and ZIP creation. The write-up lists the sample hashes and notes antivirus detections naming the malware as Kimsuky or PowerShell backdoor activity, making the script logic and artifacts useful for detecting operator-directed access.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fd23177a4481f39fe53a306e2d7fe28… 2024-03-09 2024-08-01
HASH c81ed44799aefb540123159618f7507c 2024-03-09 2024-08-01
HASH 87b5a1f79a2be17401d8b2d354c6161… 2024-03-09 2024-08-01

Related Actors

Related Reports

« Back