DropBox를 이용한 Kimsuky 악성코드

2024-03-22 Hauri ( Document No : DT-20240322-001 )

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=60

Attachments

2024-03-22ììëìë³ê³ìDropBoxë¼ììíKimsukyììì½ë.pdf (1 MB)

Hauri reports that Kimsuky has been distributing malicious Windows shortcut files since December 2023 against security-related targets and cryptocurrency investors, with a focus on information theft. The LNK execution chain runs PowerShell, uses Dropbox refresh and access tokens to retrieve encrypted payloads such as /step1/ps.bin, decrypts and executes staged scripts, and establishes persistence through scheduled tasks that run every 10 minutes. The malware collects process and service lists, system information, firewall settings, installed antivirus products, and file listings from user folders before AES-encrypting the results and uploading them to attacker-controlled Dropbox paths. Later stages include keylogging, browser credential theft, Google Drive-hosted payload retrieval, and UltraVNC deployment with a firewall rule allowing port 5900 for remote control. The report provides multiple MD5 hashes for LNK lures and related files, making it useful for tracking Kimsuky cloud-storage-based delivery and post-compromise collection tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH eb08ab3854168c834ab154facfe695a3 2024-03-22 2024-04-17
HASH 1e66ac680d0edfe18d97b89e46c7e82e 2024-03-22 2024-04-17
HASH c700195f61635b9a6fb1ee4359b91940 2024-03-22 2024-04-17
HASH fcdcc6c56ae43f7a78413cc5204e9314 2024-01-30 2024-04-17
HASH 32519b46b55792084240f850e0c94298 2024-01-30 2024-04-17
URL https://hyojadong.kr/js/slick/d… 2024-01-30 2024-03-28
DOMAIN hyojadong.kr 2024-01-30 2024-03-28
HASH c47675700b20537374c86e7a5426f848 2024-03-22 2024-03-22
HASH 886535bbe925890a01f49f49f49fee40 2024-03-22 2024-03-22

Related Actors

Related Reports

« Back