Emulating Kimsuky's Espionage Operations
2023-04-26 • Attack IQ •
https://www.attackiq.com/2023/04/26/emulating-kimsukys-espionage-operations/
AttackIQ released emulations of Kimsuky reconnaissance and espionage operations, reflecting activity against South Korean political, government, military, reunification, security, and nuclear power-related targets. The emulated chains include CHM files delivered in compressed email attachments, malicious Office documents with macros and remote templates, and AppleSeed droppers using double extensions and decoy documents. The behaviors cover living-off-the-land execution and persistence through certutil, MSHTA, WMI, registry run keys, scheduled tasks, RegSvr32, PowerShell, and service creation. Collection and exfiltration actions include system profiling, process and file discovery, antivirus discovery, keylogging, clipboard capture, AppleSeed backdoor command execution, and HTTP POST-based exfiltration. The material is useful for validating defenses against Kimsuky’s consistent social-engineering-led infection chains and reconnaissance tradecraft.