From Surveillance to Espionage: Unraveling the Latest Strategies of the Kimsuky Group
2024-08-24 • Zscaler •
Attachments
Zscaler ThreatLabZ research tracks Kimsuky activity across government, diplomatic, defense, think-tank, NGO, journalist, defector, academic, cryptocurrency, and e-commerce targets in South Korea, Japan, the United States, and other regions. The slides describe a malicious Chrome extension that abuses broad host permissions, steals email addresses and password-field values, targets login pages for Naver, Kakao, Google, and Daum, and uses a dead-drop resolver to derive a C2 URL ending in /log.php. Additional activity includes screenshot capture every five seconds, repeated ms-powerpoint:// link injection, b374k webshell use, r-e.kr-related infrastructure, and httpSpy backdoor functions such as command execution, file transfer, screenshot capture, configuration updates, and timestomping. The research also highlights overlaps among DPRK actors, including a November 2023 case where Kimsuky-like malware spread through an enterprise software update program and installed DurianBeacon, a backdoor previously identified in Andariel attacks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | r-e.kr | 2023-03-23 | 2026-06-01 |
| DOMAIN | download.uberlingen.com | 2024-06-07 | 2025-06-09 |
| HASH | 0315e137a6e2d658f07af454c63a0af2 | 2024-08-24 | 2025-05-24 |
| DOMAIN | online.viewers.r-e.kr | 2024-06-07 | 2024-08-24 |
| DOMAIN | share.dihl-defence.o-r.kr | 2024-06-07 | 2024-08-24 |
| DOMAIN | cloud.adoubleu.de | 2024-06-07 | 2024-08-24 |
| DOMAIN | ecloud.uberlingen.n-e.kr | 2024-06-07 | 2024-08-24 |
| DOMAIN | share-defence.verymad.net | 2024-06-07 | 2024-08-24 |
| DOMAIN | share-defence.ohbah.com | 2024-06-07 | 2024-08-24 |