Analyst’s Note — Kimsuky

2025-01-20 Scarlet Shark

https://blog.scarletshark.com/analysts-note-kimsuky-80a0b145ebb1

ScarletShark reported a Kimsuky, also known as Emerald Sleet, approach against a United States-based think tank using a free Proton Mail account to impersonate an employee of the Japanese Embassy in Washington, D.C. The message invited the target to a meeting, attached the impersonated staff member’s benign CV, and attempted to move the conversation to WhatsApp. Because the target did not respond, the follow-on stage was not observed, but the report assesses the tactic as likely preparation for credential phishing or malicious file delivery over an encrypted messaging channel. The documented indicators are the Proton sender address, the WhatsApp number, and the hash of the benign CV file. The case matters because it shows Kimsuky using personal email and encrypted messaging to reach policy targets where enterprise security controls may have limited visibility.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b68c90763a11b10027a10f5c17bd731… 2025-01-20 2025-01-20
EMAIL [email protected] 2025-01-20 2025-01-20

Related Actors

Related Reports

« Back