북한 해킹 조직 김수키(Kimsuky) 위장한 NDA 문서형 악성코드 유포-NDA.pdf.msc 파일 주의(2025.5.4)

2025-05-12 Sakai Distribution of NDA Document-Type Malware Disguised by North Korean Hacking Organization Kimsuky - Beware of the NDA.pdf.msc File (2025.5.4)

https://wezard4u.tistory.com/429482

Thumbnail for 북한 해킹 조직 김수키(Kimsuky) 위장한 NDA 문서형 악성코드 유포-NDA.pdf.msc 파일 주의(2025.5.4)

Kimsuky activity used an NDA.pdf.msc lure that looked like a PDF through a Microsoft Edge icon but executed as a Windows MSC file. Triple Base64-decoded content launched PowerShell to download password-protected RAR payloads and UnRAR from 109.107.157.107, extract follow-on files, and execute script content from the temporary directory. The chain dropped a decoy NDA PDF tied to a blockchain game project, hid PowerShell or Windows Terminal windows, bypassed execution policy, and repeatedly executed the extracted kaptsoli.exe payload. The source reports SHA-256 bf13fb57e2a0d8e59f9f10dbfc9edf651c70b31f4bea45abf1f085391b162e61 and vendor detections for XML or MSC downloader behavior.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4ebfb03a1339cb86051ce685c3e09c9… 2025-05-12 2025-05-12
HASH bf13fb57e2a0d8e59f9f10dbfc9edf6… 2025-05-12 2025-05-12
HASH 51c83329bb364483f122accf36ebfe76 2025-05-12 2025-05-12
IPv4 109.107.157.107 2025-05-12 2025-05-12

Related Actors

Related Reports

« Back