Kimsucky Apt Analysis

2024-03-02 somedieyoung ZZ

https://somedieyoungzz.github.io/posts/kimsucky-apt-analysis/

The analysis examines a Kimsuky-linked malicious Word document that uses social engineering to make the victim enable macros and then executes PowerShell from a temporary file. The macro writes and runs code from C:\Windows\Temp\bobo.txt, which downloads flower01.ps1 from mybobo.mygamesonline.org and establishes persistence under the current user's Run key using an Alzipupdate value. The PowerShell script gathers recent-file, program directory, system, and process information into a file named flower01.hwp under the user's roaming profile, then uploads collected data to the command-and-control server. It also includes decoding logic and download functionality for commands from the C2, supporting remote execution, file upload, file download, persistence, and system reconnaissance. The post frames this activity within Kimsuky's long-running espionage targeting of South Korean government, research, academic, and private-sector entities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 07d0be79be38ecb8c7b1c80ab0bd8344 2024-03-02 2024-03-02
HASH 1fcd9892532813a27537f4e1a1c21ec… 2020-03-20 2024-03-02
URL http://mybobo.mygamesonline.org… 2020-03-20 2024-03-02
DOMAIN mybobo.mygamesonline.org 2020-03-20 2024-03-02
IPv4 185.176.43.82 2020-03-20 2024-03-02

Related Actors

Related Reports

« Back