« 2024 »

654 reports

2024-03-02 • somedieyoung ZZ

The analysis examines a Kimsuky-linked malicious Word document that uses social engineering to make the victim enable macros and then executes PowerShell from a temporary file. The macro writes and runs code from C:\Windows\Temp\bobo.txt, which downloads …

#Kimsuky