성범죄자 고지 정보를 위장한 Kimsuky 공격

2025-09-18 Logpresso Kimsuky Attack Disguised as Sex Offender Notification Information

https://logpresso.com/ko/blog/2025-09-18-Kimsuky-Attack

Thumbnail for 성범죄자 고지 정보를 위장한 Kimsuky 공격

Logpresso attributes a July 2025 LNK-based intrusion to North Korea-linked Kimsuky, using decoy archives themed around sex offender notification and tax notice documents. The infection chain launches mshta.exe from a disguised shortcut, retrieves encrypted payloads from remote infrastructure, decrypts ZIP content with hardcoded AES material, and runs PowerShell and VBS components from the user profile. The malware collects system information, recent files, browser data, wallet extension artifacts, NPKI/GPKI certificate stores, keylogs, clipboard data, and matching document or wallet-related files before encrypting and chunking uploads to C2. It maintains persistence through a Run registry entry, avoids virtualized environments, polls C2 for upload, download, command execution, and DLL execution tasks, and references infrastructure including mailhubsec.com subdomains and 142.11.248.98. The findings matter because the campaign combines familiar Kimsuky social engineering with credential, certificate, browser, wallet, and file theft capabilities against Korean users.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1a2164d9fea343bd5a5fc31a0849bb6e 2025-09-18 2026-01-14
HASH 03794685a12ce0dd7b69e70ced8568f9 2025-09-18 2026-01-14
HASH 4aea7f8a80c27268bd68077621d69b68 2025-09-18 2026-01-14
HASH baaa2dd6942f582cd7f684b5ebc447f0 2025-09-18 2026-01-14
HASH 373fce7c6fa68ad9afa22bcbf8c15f5d 2025-09-18 2026-01-14
HASH 5eb7a909d8e8e3773b2ccc780d8f765a 2025-09-18 2026-01-14
HASH acdf153ab1211ebc840a18d2ff2221fb 2025-09-18 2026-01-14
HASH 851910eb3c05738de97d66078acc32bc 2025-09-18 2026-01-14
HASH 13d89e3f08197920230b521997135a6c 2025-09-18 2026-01-14
HASH 17b2412c1c74db7e83482a544fefacdc 2025-09-18 2026-01-14
HASH 95b0ee79eda2ea1857bda77aaaa71d92 2025-09-18 2026-01-14
HASH e45606ec936210f3830f29d0e12108c8 2025-09-18 2026-01-14
HASH 40e117a35c579a2f17eafaa728abdee3 2025-09-18 2026-01-14
HASH 444f67d186136d3deaae17a7f27b879e 2025-09-18 2026-01-14
HASH 677e77265c7ba52e825fc62023942213 2025-09-18 2026-01-14
HASH 5441d8a79411a261546beb1021cb5052 2025-09-18 2026-01-14
HASH 425e7f14bfef366725fb806c93a0e94e 2025-09-18 2026-01-14
HASH 1230b4160b399b84453fd15ed7a6f1e0 2025-09-18 2026-01-14
HASH 71a6e029ae3a56a1d5d244cdda0a93e0 2025-09-18 2026-01-14
HASH 172dc997ca6022ec8dff0842e4c7b887 2025-09-18 2026-01-14
HASH 4593e0baa7e444537730c057b1a465f3 2025-09-18 2026-01-14
HASH 9debce6651edac2a0e135a5b06f68a88 2025-09-18 2026-01-14
HASH dcb9bcd4971167905a6924c4c2cef12e 2025-09-18 2026-01-14
HASH 5852e7911d0df2473d6ed34d1ce56ff7 2025-09-18 2026-01-14
URL https://yajxu.mailhubsec.com/ 2025-09-18 2026-01-14
DOMAIN yajxu.mailhubsec.com 2025-09-18 2026-01-14
DOMAIN yfews.mailhubsec.com 2025-09-18 2026-01-14
IPv4 142.11.248.98 2025-09-18 2026-01-14
URL https://yfews.mailhubsec.com/co… 2025-09-18 2025-09-22

Related Actors

Related Reports

« Back