Kimsuky 그룹, 약력 양식 파일로 위장한 악성코드 유포 (GitHub)
2023-03-23 • Ahnlab • Kimsuky group spreads malware disguised as a profile file (GitHub) •
ASEC reports a Kimsuky campaign that impersonated a professor and emailed a password-protected Word document disguised as a biography/profile form. When macros were enabled, the document used PowerShell to contact C2, download additional scripts, and run malware consistent with earlier news-survey lure activity that steals browser-stored information. This variant changed its exfiltration method from FTP to the GitHub API, uploading suspected victim data to a specific repository. ASEC lists detections for the DOC downloader and PowerShell file-upload component and provides representative indicators including hxxp://hmcks.realma.r-e[.]kr/gl/ee.txt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 393cba61a23bf8159053e352abdd1a76 | 2023-03-23 | 2023-03-23 |
| HASH | a25acc6c420a1bb0fdc9456b4834c1b4 | 2023-03-23 | 2023-03-23 |
| URL | http://hmcks.realma.r-e.kr/gl/e… | 2023-03-23 | 2023-03-23 |
| DOMAIN | hmcks.realma.r-e.kr | 2023-03-23 | 2023-03-23 |