아동복지 기부금 사칭 악성코드 주의보 김수키(Kimsuky) 소행 분석
2025-09-01 • Sakai • Malware Alert Impersonating Child Welfare Donations: Analysis of Kimsuky Activity •
Kimsuky is attributed in the source to a Korean-language lure named “donation receipt.pdf.lnk,” which masquerades as a Hangul document and child-welfare donation receipt. When executed, the LNK launches hidden PowerShell, decodes embedded Base64 content, writes a second-stage script to the temp directory, and downloads additional payloads from GitHub and raw.githubusercontent.com. The script registers a scheduled task named “BitLocker MDM policy Refresh” for persistence, stages host-specific scripts in a GitHub repository, and uploads collected files through the GitHub API using Base64-encoded content. The activity matters because GitHub is used both as delivery infrastructure and as a data-exfiltration channel, while layered Base64 encoding, obfuscated variables, temporary-file cleanup, and hidden PowerShell execution support evasion.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3e3e9c0242bef0ff898640f50b7837e8 | 2025-09-01 | 2025-09-01 |
| HASH | fe71887782586e351888b90502a5ec7… | 2025-09-01 | 2025-09-01 |
| HASH | 5833392068b7f84ac0b4b1769e4d9ea… | 2025-09-01 | 2025-09-01 |