북한 해킹 조직 김수키(Kimsuky) 에서 만든 악성코드-한중 북중 안보현안 비공개 정책간담회 계획.lnk(2024.8.20)
2024-08-21 • Sakai • Malware Created by the North Korean Hacking Organization Kimsuky - Plan for a Private Policy Meeting on South Korea-China and North Korea-China Security Issues.lnk (2024.8.20) •
A malicious LNK file attributed in the excerpt to Kimsuky used a private policy-meeting lure about South Korea-China and North Korea-China security issues. The file masqueraded as a Hangul Word Processor document and launched hidden PowerShell that searched for the LNK, extracted embedded content, created temporary files, and executed staged payload material. The script included AES decryption logic and Dropbox API communication to download an encrypted file named ps.bin, decrypt it with the password shown in the script, and execute the resulting code through PowerShell. The lure theme and HWP disguise point to policy and North Korea-related targets, while the published MD5, SHA-1, and SHA-256 hashes support detection of this Kimsuky-linked LNK tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5b9ade0255a0f49b7db9fa8bb390864… | 2024-08-21 | 2024-08-21 |
| HASH | 6b660666f031843a36225e791f65649… | 2024-08-21 | 2024-08-21 |
| HASH | 32e828282dbe16073293dacc17f0598c | 2024-08-21 | 2024-08-21 |
| URL | https://api.dr0pb0xapi.com/oaut… | 2024-08-21 | 2024-08-21 |
| DOMAIN | cryptostream.co | 2024-08-21 | 2024-08-21 |
| DOMAIN | content.dr0pb0xapi.com | 2024-08-21 | 2024-08-21 |
| DOMAIN | api.dr0pb0xapi.com | 2024-08-21 | 2024-08-21 |