Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks

2025-02-13 Securonix

https://www.securonix.com/blog/analyzing-deepdrive-north-korean-threat-actors-observed-exploiting-trusted-platforms-for-targeted-attacks/

Thumbnail for Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks

Securonix observed the DEEP#DRIVE campaign attributed to Kimsuky targeting South Korean businesses, government entities, and cryptocurrency users with Korean-language phishing lures disguised as work logs, insurance documents, and crypto-related files. The infection chain began with ZIP-delivered LNK files masquerading as Office or PDF documents, which launched obfuscated PowerShell, decoded and executed temporary scripts, and used scheduled tasks named ChromeUpdateTaskMachine for persistence. Dropbox hosted lure documents, PowerShell payloads, and follow-on components, while scripts such as system_first.ps1 collected IP address, OS, antivirus, and process information for exfiltration. The final payload path included downloading and in-memory execution of a Gzip-compressed .NET assembly, but short-lived Dropbox infrastructure limited deeper analysis. The campaign matters because it shows Kimsuky continuing to blend trusted cloud services, local-language lures, and PowerShell-heavy staging to evade conventional defenses.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-06-19
HASH b2b8d0ae6f521f7405305a7afbe6d23… 2025-02-13 2025-02-13
HASH db6315274dc31bea8f42c79ea8928a4… 2025-02-13 2025-02-13
HASH 8d6dc026812420c5ef4b4fe72fb7067… 2025-02-13 2025-02-13
HASH ce04f9074a4cc8fa74fabff5a1fe214… 2025-02-13 2025-02-13
HASH 38b1cfb982c85ae89da19be83d50226… 2025-02-13 2025-02-13
HASH 6154932ef81ed274c492f55775713b2… 2025-02-13 2025-02-13
HASH 8e51819e39e4fc73d71b31e49b6775e… 2025-02-13 2025-02-13
HASH 8cdd557cff23ca7ddc3cf229f3b6d75… 2025-02-13 2025-02-13
HASH 074ada5cc1947ebe5b9acb7f2dbf0fa… 2025-02-13 2025-02-13
HASH 79496baa4bf17a73006a359e146f02f… 2025-02-13 2025-02-13
HASH 5171917e58a4e795a5e911f82560fa9… 2025-02-13 2025-02-13
HASH d28e8041a0445271723842fa1d400b5… 2025-02-13 2025-02-13
HASH 47dfa0061fdb021f3cefe62ac819873… 2025-02-13 2025-02-13
HASH 1d5d65f2eb065bac629c82a3399fbdc… 2025-02-13 2025-02-13
HASH 22e56ee213d9e5229371ad3e082ebfab 2025-02-13 2025-02-13
HASH db3a5a3a8855a48d2aa3ca2faef14e3… 2025-02-13 2025-02-13
HASH b960c9de6714c9951ec21ca685998ba… 2025-02-13 2025-02-13
HASH 2849d92e7e188f4b76559b7018d81f6… 2025-02-13 2025-02-13
HASH 21cefe1d3fe0c69c32bebafca15d1ad… 2025-02-13 2025-02-13
HASH fe84a4a119917f15418659ed30699d8… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-02-13
HASH 079907b7feab3673a1767dbfbc0626e… 2025-02-11 2025-02-13
HASH acbc775087da23725c3d783311d5f50… 2025-02-07 2025-02-13
HASH 71d56c61b765eee74dca65910ab9e0e… 2025-02-04 2025-02-13
URL https://dl.dropboxusercontent.c… 2024-11-27 2025-02-13
HASH 44ff60d352169f280801cf2075295aa… 2024-08-26 2025-02-13

Related Actors

Related Reports

2024-09-12 • 49% Match
#Kimsuky #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003
Shares tags: Kimsuky, T1059.003, T1567.002
« Back