북한 해킹 조직 김수키(Kimsuky)에서 만든 악성코드-SW보안점검표(개발자 사전점검용)_v2.0_beta.xlsm(2023.02.02)
2023-02-09 • Sakai • Malware created by Kimsuky disguised as a software security checklist XLSM document •
The Korean analysis attributes a malicious VBS payload disguised as a software security checklist XLSM document to Kimsuky activity targeting South Korean think tanks, industry, nuclear and defense-related organizations, and North Korea-focused personnel. The script drops files under ProgramData or the Windows directory, decodes a Base64 blob with an XOR key, registers the resulting payload with regsvr32, and uses persistence-related registry entries. Reported infrastructure includes qwert.mine[.]bz and 216.189.154[.]6:80, with detections referencing AppleSeed/Kimsuky-family VBS downloaders. The article frames the lure as part of continuing DPRK-linked social engineering against people interested in inter-Korean and security issues.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 39a61c4d9d25c8ed1b38b1a51a8ef0b… | 2023-02-09 | 2024-03-12 |
| HASH | db18e23bebb8581ba5670201cea98cc… | 2023-02-09 | 2024-03-12 |
| HASH | 12539ac37a81cc2e19338a67d237f833 | 2022-09-14 | 2024-03-12 |
| URL | http://qwert.mine.bz/index.php | 2022-09-14 | 2024-03-12 |
| DOMAIN | qwert.mine.bz | 2022-09-14 | 2024-03-12 |
| IPv4 | 216.189.154.6 | 2022-08-25 | 2024-03-12 |