Dropbox APIを使用するKimsukyのマルウェア
2026-03-17 • IIJSECT • Kimsuky Malware Using the Dropbox API •
https://sect.iij.ad.jp/blog/2026/03/dropbox-api-kimsuky-malware/
IIJ analyzed malware delivered by an LNK file uploaded from Korea and found extensive overlap with a Kimsuky campaign previously reported by AhnLab ASEC. When opened, the LNK extracted XOR-decoded components into C:\PerfLog, deployed www.ps1 and 17.vbs, and created a scheduled task named P using schtasks.exe for persistence. The PowerShell malware generated a client ID from the host MAC address, collected domain, username, OS, process, and public IP information, and uploaded the data to an attacker-controlled Dropbox folder through hardcoded Dropbox API credentials. It then checked Dropbox for a victim-specific follow-on batch file, suggesting operators reviewed collected host data before staging next payloads such as a RAT. The report highlights continued abuse of legitimate services such as Dropbox and GitHub by North Korea-linked APT activity and provides hashes and file paths for detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 29afb88a2bbff600799a42ae033e8b4… | 2026-03-17 | 2026-03-17 |
| HASH | afe9a0298d945105ee69e84bdd7c41f… | 2026-03-17 | 2026-03-17 |
| HASH | bedc8bd676a84df2e82f15a42ecec2a… | 2026-03-17 | 2026-03-17 |
| HASH | 5aca578dd7894ca29c51ce911fbb78e… | 2026-03-17 | 2026-03-17 |
| IPv4 | 208.67.222.220 | 2025-09-03 | 2026-03-17 |