북한 Kimsuky그룹의 스피어피싱을 통한 악성 LNK파일 : Powershell 백도어 설치 및 RCE 공격 절차 분석

2025-05-19 Igloo Cyber threat report on Kimsuky, LNK

https://www.igloopedia.com/1caf216a-760c-80f7-8328-d581057c6277

Thumbnail for 북한 Kimsuky그룹의 스피어피싱을 통한 악성 LNK파일 : Powershell 백도어 설치 및 RCE 공격 절차 분석

The report examines three malicious LNK files attributed to Kimsuky spear-phishing activity and groups them into two types based on C2 ports, filenames, and Google Drive details. The LNK files masquerade as .docx or .eml documents with Microsoft Word or Outlook icons and use mshta.exe to execute malicious JavaScript and PowerShell. The attack chain uses Dropbox and Google Drive to download reconnaissance code, collect and upload system information, then install a PowerShell backdoor with persistence through Run registry keys and scheduled tasks. Follow-on tooling includes PebbleDash and RDP Wrapper to enable remote control, remote execution, and additional malicious activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8ac5d4d3a68ca82b190bceb8cf7cb07e 2025-05-19 2025-05-19
HASH 3126dfaee1fc0c05f62bafcbbc49782d 2025-05-19 2025-05-19
HASH 11a100d560ebee05dd8467e5eb790c49 2025-05-19 2025-05-19
HASH e96157d3b82008c5e3142a57584678cb 2025-05-19 2025-05-19
HASH d916a1648c2de4c4e5f10fdc3f64d40d 2025-05-19 2025-05-19
HASH 2af6fb5bc3137eb297c6560e267d8193 2025-05-19 2025-05-19
HASH f792d1864e7e92fe25daa73fe964bdea 2025-05-19 2025-05-19
HASH 5fca1117c0e5ee6de3c169eebc903227 2025-05-19 2025-05-19
HASH 42f2dbc68c6a4844474c695bf8000420 2025-05-19 2025-05-19
HASH 2c98bfc9f76352c82dc57edd98dce9a8 2025-05-19 2025-05-19
HASH 8b541e4da55cb41e3304bda5ea568eb7 2025-05-19 2025-05-19
HASH 5e040663bbe55915a67f696a6aafb81a 2025-05-19 2025-05-19
HASH 85cdfd80e45269c30948dc642f4070a5 2025-05-19 2025-05-19
HASH c0375790762356a5652719b97a7b5602 2025-05-19 2025-05-19
HASH ca9b8df227469c7e6d745cc267db80ba 2025-05-19 2025-05-19
HASH 99f9419d756729bc97d687f845d77783 2025-05-19 2025-05-19
HASH 0d6f3ce0c314e611f4e933dd6c17f2e3 2025-05-19 2025-05-19
HASH a573b15586e4313832f269b162a04514 2025-05-19 2025-05-19
HASH ae6ebf3fcde78bb6da37e302a2a579ee 2025-05-19 2025-05-19
HASH 9f1c9fc7aa773e7a86a79180c42887e1 2025-05-19 2025-05-19
HASH 245d729238809b580179b70b7347cf65 2025-05-19 2025-05-19
URL https://www.dropbox.com/scl/fi/… 2025-05-19 2025-05-19
URL https://www.dropbox.com/scl/fi/… 2025-05-19 2025-05-19
URL https://www.dropbox.com/scl/fi/… 2025-05-19 2025-05-19
HASH 31345cc286bfb2b3edcee6c960f11c3f 2025-05-08 2025-05-19
HASH 15dc6a28b875b4706bcc0db4a026aeb0 2025-04-13 2025-05-19
DOMAIN 71532697854-ef1nlsl4cjn4scm57ds… 2025-03-12 2025-05-19
DOMAIN 159263970130-1gil63rpicrhtbo4he… 2025-03-12 2025-05-19
IPv4 74.50.94.175 2025-03-12 2025-05-19
HASH 7349683077ce4fcac77580848182ead9 2025-02-13 2025-05-19
HASH 1e9d94d88fdac3c4a0a47a3a1d07e329 2025-02-12 2025-05-19

Related Actors

Related Reports

« Back