APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析

2026-05-13 Qihoo360 Analysis of an APT-C-55 (Kimsuky) Attack Campaign Distributing Malicious Payloads via GitHub and Dropbox

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508584&idx=1&sn=3983faed8f799809ecc23eb552e73548&scene=178

Thumbnail for APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析

Kimsuky, also tracked as APT-C-55 and BabyShark, is described as an espionage-focused actor that targets government, diplomatic, think tank, media, and academic organizations tied to the Korean Peninsula and other regions. The observed campaign begins with a phishing LNK file named as a Korean-language China CMG interview document, which decrypts and opens a decoy while using a copied curl binary to download taskschd.vbs from Dropbox. The VBS stage pulls a batch script from GitHub, which then downloads two PowerShell scripts from Dropbox and GitHub. One PowerShell script creates a GoogleUpdateTaskMachineUA-named scheduled task for persistence and uploads host information to GitHub, while the other decrypts content from fox.png with a modified RC4 routine and reflectively loads a .NET payload identified as an AsyncRAT variant for sensitive information theft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 112.216.9.171 2026-05-13 2026-05-13
URL https://raw.githubusercontent.c… 2026-05-13 2026-05-13
URL https://raw.githubusercontent.c… 2026-05-13 2026-05-13
URL https://www.dropbox.com/scl/fi/… 2026-05-13 2026-05-13
URL https://raw.githubusercontent.c… 2026-05-13 2026-05-13
URL https://www.dropbox.com/scl/fi/… 2026-05-13 2026-05-13
HASH 849ddfdba810b251522690d51475a359 2026-05-13 2026-05-13
HASH 02ebc2356f9f700bbdac444cdefa0da2 2026-05-13 2026-05-13
HASH 73ff669fc282653bd6c42cf87ade9337 2026-05-13 2026-05-13
HASH 45b6b7dadc13e4a4cc30dd82eb58c3ed 2026-05-13 2026-05-13
HASH 23da5ff2ed7bd4ac5a2a148afc037b6a 2026-05-13 2026-05-13
HASH b406ea5b8628cb7801f47c0189b96182 2026-05-13 2026-05-13
HASH e0e4aec6d494fe68cdaa52d6878a8366 2026-05-13 2026-05-13
HASH d9d7d5feb2abc828b58142fc63509d80 2026-05-13 2026-05-13
HASH 0d8ceb7dea7d471afa2f8e753b13d2d6 2026-05-13 2026-05-13
HASH bd17b8b10675031cec05c0cd8a001fac 2026-05-13 2026-05-13
HASH ba8e682a72c6a3e634c070f0fb057bf5 2026-05-13 2026-05-13

Related Actors

Related Reports

« Back