kakaoTest.exe 파일명의 Kimsuky 제작 추정 악성코드

2021-09-10 Ahnlab Malicious code estimated to be created by Kimsuky with the file name kakaoTest.exe

https://asec.ahnlab.com/ko/26917

Thumbnail for kakaoTest.exe 파일명의 Kimsuky 제작 추정 악성코드

ASEC analyzed kakaoTest.exe, a suspected Kimsuky-developed test malware that reused code seen in earlier malicious documents and the related pagefile.sys component. The sample reads credentials and transfer parameters from test.ini, logs in to a Daum mail account, uploads a specified file, and sends it to a configured receiver while also querying Daum mail URLs such as address-book pages. The overlap with prior Kimsuky tooling indicates continued development of mail-abuse malware for file collection and exfiltration, even though the filename and configuration suggest this sample was still in a testing stage.

Related Actors

Related Reports

« Back