Kimsuky(김수키) 대한민국 국회 보안 문서 [자문]북한 신형 자폭드론 으로 위장한 악성코드(2024.9.12)

2024-11-22 Sakai Malware by Kimsuky Disguised as a Republic of Korea National Assembly Security Document, [Advisory] North Korea's New Suicide Drones (2024.9.12)

https://wezard4u.tistory.com/429337

Thumbnail for Kimsuky(김수키) 대한민국 국회 보안 문서 [자문]북한 신형 자폭드론 으로 위장한 악성코드(2024.9.12)

Kimsuky is linked to a malicious MSC file disguised as a South Korean National Assembly advisory about North Korea's new suicide drones. The lure opens a Google Docs decoy while command-line logic downloads files from petssecondchance.larcity.dev into Public Music and Pictures directories, renames them as XML and VBS artifacts, and creates scheduled tasks named TerminalServiceUpdater and TermServiceUpdater. The infection chain uses Microsoft Management Console content to run hidden commands, fetch payloads from CSS-looking paths, and establish persistence through Windows Task Scheduler. The excerpt provides hashes for the MSC sample and multiple file paths and URLs that defenders can use to hunt for related activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f535a3faed62e48d588e190f372785a… 2024-11-22 2024-11-22
URL https://petssecondchance.larcit… 2024-11-22 2024-11-22
HASH 391fa4e57f91e3422ef5d32523d4dfc7 2024-10-04 2024-11-22
HASH 57e9b7d1c18684a4e8b3688c454e832… 2024-09-14 2024-11-22
URL https://petssecondchance.larcit… 2024-09-14 2024-11-22
URL https://petssecondchance.larcit… 2024-09-13 2024-11-22
URL https://petssecondchance.larcit… 2024-09-13 2024-11-22
URL https://petssecondchance.larcit… 2024-09-13 2024-11-22
DOMAIN petssecondchance.larcity.dev 2024-09-13 2024-11-22

Related Actors

Related Reports

« Back