Dissecting the Infection Chain: Technical Analysis of the Kimsuky JavaScript Dropper

2025-11-05 Pulsedive

https://blog.pulsedive.com/dissecting-the-infection-chain-technical-analysis-of-the-kimsuky-javascript-dropper/

Thumbnail for Dissecting the Infection Chain: Technical Analysis of the Kimsuky JavaScript Dropper

The Pulsedive analysis examines a Kimsuky JavaScript dropper tied to public IOCs and sandbox traffic for a North Korean espionage group active against government, think-tank, and expert targets. The initial script contacts iuh234[.]medianewsonline[.]com through dwnkl[.]php with the host computer name, retrieves additional JavaScript, and executes server-supplied content. The second stage collects system information, running processes, and file listings from the Users directory, packages output into cabinet files with certutil, and exfiltrates the data by POST requests to the same infrastructure. A third-stage script writes Themes.js under the Windows Themes path and creates a scheduled task named Windows Theme Manager for minute-by-minute persistence, while also dropping an apparently empty Word document lure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 596cd0d30fe035e8be1dd9d78c1f71a… 2025-11-05 2025-11-05
DOMAIN iuh234.medianewsonline.com 2025-11-05 2025-11-05

Related Actors

Related Reports

« Back