From Surveillance to Espionage: Unraveling the Latest Strategies of the Kimsuky Group

2024-08-24 Zscaler

https://hitcon.org/2024/CMT/slides/From_Surveillance_to_Espionage_Unraveling_the_Latest_Strategies_of_the_Kimsuky_Group.pdf

Attachments

From_Surveillance_to_Espionage_Unraveling_the_Latest_Strategies_of_uU7IQCT.pdf (5 MB)

Thumbnail for From Surveillance to Espionage: Unraveling the Latest Strategies of the Kimsuky Group

Zscaler ThreatLabZ research tracks Kimsuky activity across government, diplomatic, defense, think-tank, NGO, journalist, defector, academic, cryptocurrency, and e-commerce targets in South Korea, Japan, the United States, and other regions. The slides describe a malicious Chrome extension that abuses broad host permissions, steals email addresses and password-field values, targets login pages for Naver, Kakao, Google, and Daum, and uses a dead-drop resolver to derive a C2 URL ending in /log.php. Additional activity includes screenshot capture every five seconds, repeated ms-powerpoint:// link injection, b374k webshell use, r-e.kr-related infrastructure, and httpSpy backdoor functions such as command execution, file transfer, screenshot capture, configuration updates, and timestomping. The research also highlights overlaps among DPRK actors, including a November 2023 case where Kimsuky-like malware spread through an enterprise software update program and installed DurianBeacon, a backdoor previously identified in Andariel attacks.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN r-e.kr 2023-03-23 2026-06-01
DOMAIN download.uberlingen.com 2024-06-07 2025-06-09
HASH 0315e137a6e2d658f07af454c63a0af2 2024-08-24 2025-05-24
DOMAIN online.viewers.r-e.kr 2024-06-07 2024-08-24
DOMAIN share.dihl-defence.o-r.kr 2024-06-07 2024-08-24
DOMAIN cloud.adoubleu.de 2024-06-07 2024-08-24
DOMAIN ecloud.uberlingen.n-e.kr 2024-06-07 2024-08-24
DOMAIN share-defence.verymad.net 2024-06-07 2024-08-24
DOMAIN share-defence.ohbah.com 2024-06-07 2024-08-24

Related Actors

Related Reports

« Back