북한 해킹 단체 김수키(Kimsuky)에서 만든 PowerShell 백도어 도구(2024.2.29)
2024-08-01 • Sakai • PowerShell Backdoor Tool Created by the North Korean Hacking Group Kimsuky (2024.2.29) •
The excerpt analyzes a Kimsuky-attributed PowerShell backdoor that repeatedly connects to a server, sleeps between attempts, and continues until the server instructs it to close. The script generates a victim identifier from the host's MAC and IPv4 address, prepares RC4 send and receive keys, and sends an initial unique-ID packet over a TCP socket. Its RemoteFileManager functionality defines commands for drive and path listing, file download and upload, deletion, renaming, directory creation, execution, restart, removal, and ZIP creation. The write-up lists the sample hashes and notes antivirus detections naming the malware as Kimsuky or PowerShell backdoor activity, making the script logic and artifacts useful for detecting operator-directed access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fd23177a4481f39fe53a306e2d7fe28… | 2024-03-09 | 2024-08-01 |
| HASH | c81ed44799aefb540123159618f7507c | 2024-03-09 | 2024-08-01 |
| HASH | 87b5a1f79a2be17401d8b2d354c6161… | 2024-03-09 | 2024-08-01 |