Kimsuky(김수키)에서 만든 공적조서(개인,양식)로 위장한 악성코드

2025-01-21 Sakai Kimsuky Malware Disguised as a Public Service Citation Personal Form

https://wezard4u.tistory.com/429386

Thumbnail for Kimsuky(김수키)에서 만든 공적조서(개인,양식)로 위장한 악성코드

The report analyzes Kimsuky malware delivered as a Windows LNK file disguised as a public service citation personal form. The lure executes PowerShell commands after the victim opens the shortcut, indicating a social-engineering intrusion path consistent with document-themed DPRK phishing operations. The evidence supports tracking the file name, command-line behavior, and associated script execution as Kimsuky-linked malware activity targeting Korean-language users.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7df7ad7b88887a06b559cd453e7b652… 2025-01-21 2025-03-10
HASH 5adfa76b72236bf017f7968fd012e968 2025-01-21 2025-02-19
DOMAIN hvil-telegram.org 2025-01-15 2025-01-24
HASH 5f0d09853fb459500237105201bbf33… 2025-01-21 2025-01-21

Related Actors

Related Reports

« Back