아동복지 기부금 사칭 악성코드 주의보 김수키(Kimsuky) 소행 분석

2025-09-01 Sakai Malware Alert Impersonating Child Welfare Donations: Analysis of Kimsuky Activity

https://wezard4u.tistory.com/429584

Thumbnail for 아동복지 기부금 사칭 악성코드 주의보 김수키(Kimsuky) 소행 분석

Kimsuky is attributed in the source to a Korean-language lure named “donation receipt.pdf.lnk,” which masquerades as a Hangul document and child-welfare donation receipt. When executed, the LNK launches hidden PowerShell, decodes embedded Base64 content, writes a second-stage script to the temp directory, and downloads additional payloads from GitHub and raw.githubusercontent.com. The script registers a scheduled task named “BitLocker MDM policy Refresh” for persistence, stages host-specific scripts in a GitHub repository, and uploads collected files through the GitHub API using Base64-encoded content. The activity matters because GitHub is used both as delivery infrastructure and as a data-exfiltration channel, while layered Base64 encoding, obfuscated variables, temporary-file cleanup, and hidden PowerShell execution support evasion.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3e3e9c0242bef0ff898640f50b7837e8 2025-09-01 2025-09-01
HASH fe71887782586e351888b90502a5ec7… 2025-09-01 2025-09-01
HASH 5833392068b7f84ac0b4b1769e4d9ea… 2025-09-01 2025-09-01

Related Actors

Related Reports

« Back