Kimsuky武器库更新:利用新冠疫情为诱饵针对韩国地区的攻击活动分析

2021-10-12 Qianxin Kimsuky arsenal update: analysis of attacks targeting South Korea using the COVID-19 epidemic as bait

https://ti.qianxin.com/blog/articles/Kimsuky-Weapon-Update:-Analysis-of-Attack-Activity-Targeting-Korean-Region/

Thumbnail for Kimsuky武器库更新:利用新冠疫情为诱饵针对韩国地区的攻击活动分析

QiAnXin analyzed a Kimsuky-attributed attack against South Korean targets that used COVID-19 response material tied to a local land-management office as the lure. The malware arrived as a PIF executable masquerading as a PDF, acting as a loader that decrypted API strings, wrote both decoy and payload files under C:\ProgramData\, and launched the next stage with a fixed parameter. The payload copied itself as smss.exe under a system32-named folder, configured registry-based startup persistence, and included a file-deletion routine that overwrote, renamed, and removed target files. QiAnXin linked the activity to Kimsuky through malware analysis and infrastructure overlap, including reuse of IP address 216.189.149.78 and the domain movie.youtoboo.kro.kr.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 946f787c129bf469298aa881fb0843f4 2021-10-12 2021-10-12
HASH e33a34fa0e0696f6eae4feba11873f56 2021-10-12 2021-10-12
DOMAIN movie.youtoboo.kro.kr 2021-10-12 2021-10-12
IPv4 216.189.149.78 2021-10-12 2021-10-12

Related Actors

Related Reports

« Back