북한 해킹 조직 김수키(Kimsuky)에서 만든 악성코드-SW보안점검표(개발자 사전점검용)_v2.0_beta.xlsm(2023.02.02)

2023-02-09 Sakai Malware created by Kimsuky disguised as a software security checklist XLSM document

https://wezard4u.tistory.com/6357

Thumbnail for 북한 해킹 조직 김수키(Kimsuky)에서 만든 악성코드-SW보안점검표(개발자 사전점검용)_v2.0_beta.xlsm(2023.02.02)

The Korean analysis attributes a malicious VBS payload disguised as a software security checklist XLSM document to Kimsuky activity targeting South Korean think tanks, industry, nuclear and defense-related organizations, and North Korea-focused personnel. The script drops files under ProgramData or the Windows directory, decodes a Base64 blob with an XOR key, registers the resulting payload with regsvr32, and uses persistence-related registry entries. Reported infrastructure includes qwert.mine[.]bz and 216.189.154[.]6:80, with detections referencing AppleSeed/Kimsuky-family VBS downloaders. The article frames the lure as part of continuing DPRK-linked social engineering against people interested in inter-Korean and security issues.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 39a61c4d9d25c8ed1b38b1a51a8ef0b… 2023-02-09 2024-03-12
HASH db18e23bebb8581ba5670201cea98cc… 2023-02-09 2024-03-12
HASH 12539ac37a81cc2e19338a67d237f833 2022-09-14 2024-03-12
URL http://qwert.mine.bz/index.php 2022-09-14 2024-03-12
DOMAIN qwert.mine.bz 2022-09-14 2024-03-12
IPv4 216.189.154.6 2022-08-25 2024-03-12

Related Actors

Related Reports

« Back