Kimsuky(김수키)에서 만든 공적조서(개인,양식)로 위장한 악성코드
2025-01-21 • Sakai • Kimsuky Malware Disguised as a Public Service Citation Personal Form •
The report analyzes Kimsuky malware delivered as a Windows LNK file disguised as a public service citation personal form. The lure executes PowerShell commands after the victim opens the shortcut, indicating a social-engineering intrusion path consistent with document-themed DPRK phishing operations. The evidence supports tracking the file name, command-line behavior, and associated script execution as Kimsuky-linked malware activity targeting Korean-language users.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7df7ad7b88887a06b559cd453e7b652… | 2025-01-21 | 2025-03-10 |
| HASH | 5adfa76b72236bf017f7968fd012e968 | 2025-01-21 | 2025-02-19 |
| DOMAIN | hvil-telegram.org | 2025-01-15 | 2025-01-24 |
| HASH | 5f0d09853fb459500237105201bbf33… | 2025-01-21 | 2025-01-21 |
Related Actors
Related Reports
Shares tags: Kimsuky, LNK • Same author: Sakai • Published within a month
Shares tags: Kimsuky, LNK • Same author: Sakai • Published within a month
Shares tags: Kimsuky, LNK • Same author: Sakai
Shares tags: Kimsuky, LNK • Same author: Sakai
Shares tags: Kimsuky, LNK • Same author: Sakai
2025-02-13 •
80% Match
Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks
Securonix
Shares tags: Kimsuky, LNK • Published within a month