Dropbox를 이용한 Kimsuky 공격 그룹의 최신 정보 탈취 사례
2025-06-30 • Plainbit • Cyber threat report on Kimsuky •
Attachments
Plainbit and South Korea's NCSC document a May 2025 Kimsuky/APT43 phishing case against an activist working on North Korea issues. The actor sent repeated spear-phishing emails that impersonated Sejong Institute staff and nuclear security forum themes, using MEGA links to ZIP files containing malicious LNK shortcuts. When opened, the LNK launched PowerShell that downloaded additional malware, collected host data such as process and OS details, and used Dropbox as a C2 channel to upload system information and receive follow-on commands. The report ties the activity to Kimsuky through overlap with prior techniques, including malicious shortcut execution, cloud-service abuse, and staged payload retrieval.