킴수키(Kimsuky)조직, '협의 이혼 의사 확인 신청서'를 위장한 QuasarRAT 유포 중!
2023-03-15 • ESTSecurity • Kimsuky distributing QuasarRAT disguised as an application to confirm intent to divorce •
Kimsuky distributed a malicious Word document masquerading as an application to confirm mutual intent to divorce, using macros to install QuasarRAT. When the user enabled content, the decoy displayed a legitimate-looking divorce form while AutoOpen macro logic contacted attacker-controlled infrastructure, dropped version.ini, runps.vbs and conf.ps1, and repeatedly downloaded additional payloads before launching QuasarRAT. ESRC linked the activity to a North Korea-backed APT Smoke Screen operation and noted detections such as Trojan.Downloader.DOC.Gen, Backdoor.MSIL.Quasar.gen and Trojan.PowerShell.Agent, with C2 details withheld because the server remained reachable.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3c687fb0a1921a53f9c607938f25fdd1 | 2023-03-15 | 2023-05-24 |
| HASH | d4bb07f5a9462612cd0e8a9290e27fc8 | 2023-03-15 | 2023-05-24 |
| HASH | 8f411a46490016ac5d126b83cee65022 | 2023-03-15 | 2023-05-24 |
| HASH | e0cf0881de0fe35732bb02c1f4df02a3 | 2023-03-15 | 2023-05-24 |