Dropbox APIを使用するKimsukyのマルウェア

2026-03-17 IIJSECT Kimsuky Malware Using the Dropbox API

https://sect.iij.ad.jp/blog/2026/03/dropbox-api-kimsuky-malware/

Thumbnail for Dropbox APIを使用するKimsukyのマルウェア

IIJ analyzed malware delivered by an LNK file uploaded from Korea and found extensive overlap with a Kimsuky campaign previously reported by AhnLab ASEC. When opened, the LNK extracted XOR-decoded components into C:\PerfLog, deployed www.ps1 and 17.vbs, and created a scheduled task named P using schtasks.exe for persistence. The PowerShell malware generated a client ID from the host MAC address, collected domain, username, OS, process, and public IP information, and uploaded the data to an attacker-controlled Dropbox folder through hardcoded Dropbox API credentials. It then checked Dropbox for a victim-specific follow-on batch file, suggesting operators reviewed collected host data before staging next payloads such as a RAT. The report highlights continued abuse of legitimate services such as Dropbox and GitHub by North Korea-linked APT activity and provides hashes and file paths for detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 29afb88a2bbff600799a42ae033e8b4… 2026-03-17 2026-03-17
HASH afe9a0298d945105ee69e84bdd7c41f… 2026-03-17 2026-03-17
HASH bedc8bd676a84df2e82f15a42ecec2a… 2026-03-17 2026-03-17
HASH 5aca578dd7894ca29c51ce911fbb78e… 2026-03-17 2026-03-17
IPv4 208.67.222.220 2025-09-03 2026-03-17

Related Actors

Related Reports

« Back