Analysis of Kimsuky APT Group (Powershell Payloads one of them attributed to XWorm RAT)
2025-05-12 • Shubho57 •
The Medium analysis reviews two Base64-encoded PowerShell payloads attributed to Kimsuky-related activity and XWorm RAT. After decoding, the scripts show staged behavior: PowerShell and CMD execution, fileless or obfuscated script execution, download of archives and executables from a single malicious IP, decoy PDF display, and use of ExecutionPolicy Bypass for later-stage payloads. The write-up also notes process-window hiding through Win32 API calls, registry and system discovery, event logging disruption, and C2 communication for payload retrieval or attacker commands. Although the evidence is analyst-written and figure-dependent, the distinctive CTI value is the overlap between Kimsuky-labelled PowerShell staging and commodity RAT-style remote access behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | Inline_CSharp_ShowWindow_Hider | 2025-05-12 | 2025-05-12 |
| IPv4 | 92.119.114.128 | 2025-05-12 | 2025-05-12 |
| IPv4 | 185.235.128.114 | 2025-05-12 | 2025-05-12 |