« 2023 »

627 reports

2023-11-24 • Secu I

SECUi describes 2023 Kimsuky attacks in South Korea that used ZIP archives containing a decoy document and an LNK file disguised as a document to start reconnaissance malware. The LNK embeds obfuscated PowerShell, a lure document, and script modules; exec…

#Kimsuky #LNK