북한 해킹 조직 김수키(Kimsuky) 위장한 NDA 문서형 악성코드 유포-NDA.pdf.msc 파일 주의(2025.5.4)
2025-05-12 • Sakai • Distribution of NDA Document-Type Malware Disguised by North Korean Hacking Organization Kimsuky - Beware of the NDA.pdf.msc File (2025.5.4) •
Kimsuky activity used an NDA.pdf.msc lure that looked like a PDF through a Microsoft Edge icon but executed as a Windows MSC file. Triple Base64-decoded content launched PowerShell to download password-protected RAR payloads and UnRAR from 109.107.157.107, extract follow-on files, and execute script content from the temporary directory. The chain dropped a decoy NDA PDF tied to a blockchain game project, hid PowerShell or Windows Terminal windows, bypassed execution policy, and repeatedly executed the extracted kaptsoli.exe payload. The source reports SHA-256 bf13fb57e2a0d8e59f9f10dbfc9edf651c70b31f4bea45abf1f085391b162e61 and vendor detections for XML or MSC downloader behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4ebfb03a1339cb86051ce685c3e09c9… | 2025-05-12 | 2025-05-12 |
| HASH | bf13fb57e2a0d8e59f9f10dbfc9edf6… | 2025-05-12 | 2025-05-12 |
| HASH | 51c83329bb364483f122accf36ebfe76 | 2025-05-12 | 2025-05-12 |
| IPv4 | 109.107.157.107 | 2025-05-12 | 2025-05-12 |