Kimsuky(김수키) 대한민국 국회 보안 문서 [자문]북한 신형 자폭드론 으로 위장한 악성코드(2024.9.12)
2024-11-22 • Sakai • Malware by Kimsuky Disguised as a Republic of Korea National Assembly Security Document, [Advisory] North Korea's New Suicide Drones (2024.9.12) •
Kimsuky is linked to a malicious MSC file disguised as a South Korean National Assembly advisory about North Korea's new suicide drones. The lure opens a Google Docs decoy while command-line logic downloads files from petssecondchance.larcity.dev into Public Music and Pictures directories, renames them as XML and VBS artifacts, and creates scheduled tasks named TerminalServiceUpdater and TermServiceUpdater. The infection chain uses Microsoft Management Console content to run hidden commands, fetch payloads from CSS-looking paths, and establish persistence through Windows Task Scheduler. The excerpt provides hashes for the MSC sample and multiple file paths and URLs that defenders can use to hunt for related activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f535a3faed62e48d588e190f372785a… | 2024-11-22 | 2024-11-22 |
| URL | https://petssecondchance.larcit… | 2024-11-22 | 2024-11-22 |
| HASH | 391fa4e57f91e3422ef5d32523d4dfc7 | 2024-10-04 | 2024-11-22 |
| HASH | 57e9b7d1c18684a4e8b3688c454e832… | 2024-09-14 | 2024-11-22 |
| URL | https://petssecondchance.larcit… | 2024-09-14 | 2024-11-22 |
| URL | https://petssecondchance.larcit… | 2024-09-13 | 2024-11-22 |
| URL | https://petssecondchance.larcit… | 2024-09-13 | 2024-11-22 |
| URL | https://petssecondchance.larcit… | 2024-09-13 | 2024-11-22 |
| DOMAIN | petssecondchance.larcity.dev | 2024-09-13 | 2024-11-22 |