GitLab 플랫폼을 이용한 Kimsuky 공격 사례
2026-04-03 • ESTSecurity • Kimsuky attack case using the GitLab platform •
Kimsuky is assessed to have distributed malicious `.pdf.lnk` files disguised as a resume and North Korea policy documents, using a multi-stage PowerShell chain to collect host information and exfiltrate it. The infection saves and runs `firefox.ps1`, establishes persistence with a Microsoft Edge-themed scheduled task, deploys `facebook.ps1` as a recurring downloader, and executes `news.ps1` as the final information-stealing payload. The campaign abuses GitLab rather than previously observed GitHub infrastructure, using GitLab-hosted encrypted payload files and the GitLab API to upload AES-256-encrypted victim data. ESRC lists two LNK MD5 hashes and two GitLab repository URLs as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://gitlab.com/kevin-group5… | 2026-04-03 | 2026-04-03 |
| URL | https://gitlab.com/arkiler-grou… | 2026-04-03 | 2026-04-03 |
| HASH | 302725413076d1aeaee2d7f2b3692646 | 2026-04-03 | 2026-04-03 |
| HASH | 5577fffb5b5acd3771ef9dc696498f1e | 2026-04-03 | 2026-04-03 |