북한 해킹 조직 김수키(Kimsuky) 에서 만든 악성코드-한중 북중 안보현안 비공개 정책간담회 계획.lnk(2024.8.20)

2024-08-21 Sakai Malware Created by the North Korean Hacking Organization Kimsuky - Plan for a Private Policy Meeting on South Korea-China and North Korea-China Security Issues.lnk (2024.8.20)

https://wezard4u.tistory.com/429258

Thumbnail for 북한 해킹 조직 김수키(Kimsuky) 에서 만든 악성코드-한중 북중 안보현안 비공개 정책간담회 계획.lnk(2024.8.20)

A malicious LNK file attributed in the excerpt to Kimsuky used a private policy-meeting lure about South Korea-China and North Korea-China security issues. The file masqueraded as a Hangul Word Processor document and launched hidden PowerShell that searched for the LNK, extracted embedded content, created temporary files, and executed staged payload material. The script included AES decryption logic and Dropbox API communication to download an encrypted file named ps.bin, decrypt it with the password shown in the script, and execute the resulting code through PowerShell. The lure theme and HWP disguise point to policy and North Korea-related targets, while the published MD5, SHA-1, and SHA-256 hashes support detection of this Kimsuky-linked LNK tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5b9ade0255a0f49b7db9fa8bb390864… 2024-08-21 2024-08-21
HASH 6b660666f031843a36225e791f65649… 2024-08-21 2024-08-21
HASH 32e828282dbe16073293dacc17f0598c 2024-08-21 2024-08-21
URL https://api.dr0pb0xapi.com/oaut… 2024-08-21 2024-08-21
DOMAIN cryptostream.co 2024-08-21 2024-08-21
DOMAIN content.dr0pb0xapi.com 2024-08-21 2024-08-21
DOMAIN api.dr0pb0xapi.com 2024-08-21 2024-08-21

Related Actors

Related Reports

« Back