GitLab 플랫폼을 이용한 Kimsuky 공격 사례

2026-04-03 ESTSecurity Kimsuky attack case using the GitLab platform

https://blog.alyac.co.kr/5743

Thumbnail for GitLab 플랫폼을 이용한 Kimsuky 공격 사례

Kimsuky is assessed to have distributed malicious `.pdf.lnk` files disguised as a resume and North Korea policy documents, using a multi-stage PowerShell chain to collect host information and exfiltrate it. The infection saves and runs `firefox.ps1`, establishes persistence with a Microsoft Edge-themed scheduled task, deploys `facebook.ps1` as a recurring downloader, and executes `news.ps1` as the final information-stealing payload. The campaign abuses GitLab rather than previously observed GitHub infrastructure, using GitLab-hosted encrypted payload files and the GitLab API to upload AES-256-encrypted victim data. ESRC lists two LNK MD5 hashes and two GitLab repository URLs as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://gitlab.com/kevin-group5… 2026-04-03 2026-04-03
URL https://gitlab.com/arkiler-grou… 2026-04-03 2026-04-03
HASH 302725413076d1aeaee2d7f2b3692646 2026-04-03 2026-04-03
HASH 5577fffb5b5acd3771ef9dc696498f1e 2026-04-03 2026-04-03

Related Actors

Related Reports

2026-04-17 • 62% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing, T1027 • Published within a month
2026-01-13 • 56% Match
#Kimsuky #T1102.002 #T1059.003 #T1567.002 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1059.005 #T1583.006 #T1566.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1566 #T1585.001 #T1656 #T1205 #T1105 #T1055 #T1553.002 #T1620 #T1102.001 #T1027.002 #T1133 #T1190 #T1593 #T1588.002 #T1657 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1585 #T1593.002 #T1598 #T1583 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1588.003 #T1589.003 #T1594 #T1218.010 #T1557 #T1219.002 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1596
Shares tags: Kimsuky, T1567.002, T1070.004
« Back