Analysis of Kimsuky APT Group (Powershell Payloads one of them attributed to XWorm RAT)

2025-05-12 Shubho57

https://medium.com/@shubhandrew/analysis-of-kimsuky-apt-group-powershell-payloads-one-of-them-attributed-to-xworm-rat-ea8a96ea53fe

The Medium analysis reviews two Base64-encoded PowerShell payloads attributed to Kimsuky-related activity and XWorm RAT. After decoding, the scripts show staged behavior: PowerShell and CMD execution, fileless or obfuscated script execution, download of archives and executables from a single malicious IP, decoy PDF display, and use of ExecutionPolicy Bypass for later-stage payloads. The write-up also notes process-window hiding through Win32 API calls, registry and system discovery, event logging disruption, and C2 communication for payload retrieval or attacker commands. Although the evidence is analyst-written and figure-dependent, the distinctive CTI value is the overlap between Kimsuky-labelled PowerShell staging and commodity RAT-style remote access behavior.

Indicators of Compromise

Type Value First Seen Last Seen
YARA Inline_CSharp_ShowWindow_Hider 2025-05-12 2025-05-12
IPv4 92.119.114.128 2025-05-12 2025-05-12
IPv4 185.235.128.114 2025-05-12 2025-05-12

Related Actors

Related Reports

« Back