파이썬 기반 백도어를 유포하는 악성 LNK 및 유포 방식의 변화 (Kimsuky 그룹)
2026-04-01 • Ahnlab • Changes in Malicious LNK Distribution Methods Delivering Python-Based Backdoors (Kimsuky Group) •
AhnLab ASEC reported a shift in Kimsuky’s malicious LNK delivery method for Python-based backdoors and downloaders. The newer chain uses document-themed LNK lures, hidden files under C:\windirr, XML Task Scheduler entries, VBS and PowerShell scripts, Dropbox-based staging, and split ZIP downloads that unpack a Python backdoor to C:\winii. The backdoor communicates with 45.95.186[.]232:8080, signals infection with “HAPPY,” and supports operator commands for shell execution, drive checks, directory listing, file upload and download, secure deletion, and launching executable or script files. AhnLab cites overlaps with prior Kimsuky tradecraft, including similar GoogleUpdate-style task names, sch_*.db scheduler XML files, and reused decoy documents, showing continued adaptation of the same LNK-based infection model.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://qugesr.online/m/bDw | 2026-04-01 | 2026-04-14 |
| DOMAIN | qugesr.online | 2026-04-01 | 2026-04-14 |
| IPv4 | 45.95.186.232 | 2026-04-01 | 2026-04-14 |
| URL | https://quickcon.store/man/logo… | 2026-04-01 | 2026-04-01 |
| URL | https://qugesr.online/dwparts_v… | 2026-04-01 | 2026-04-01 |
| URL | https://qugesr.online/dwparts_v… | 2026-04-01 | 2026-04-01 |
| URL | https://quickcon.store/man/logo… | 2026-04-01 | 2026-04-01 |
| URL | https://qugesr.online/dwparts_v… | 2026-04-01 | 2026-04-01 |
| DOMAIN | quickcon.store | 2026-04-01 | 2026-04-01 |