Kimsuky 그룹, 약력 양식 파일로 위장한 악성코드 유포 (GitHub)

2023-03-23 Ahnlab Kimsuky group spreads malware disguised as a profile file (GitHub)

https://asec.ahnlab.com/ko/50275/

Thumbnail for Kimsuky 그룹, 약력 양식 파일로 위장한 악성코드 유포 (GitHub)

ASEC reports a Kimsuky campaign that impersonated a professor and emailed a password-protected Word document disguised as a biography/profile form. When macros were enabled, the document used PowerShell to contact C2, download additional scripts, and run malware consistent with earlier news-survey lure activity that steals browser-stored information. This variant changed its exfiltration method from FTP to the GitHub API, uploading suspected victim data to a specific repository. ASEC lists detections for the DOC downloader and PowerShell file-upload component and provides representative indicators including hxxp://hmcks.realma.r-e[.]kr/gl/ee.txt.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 393cba61a23bf8159053e352abdd1a76 2023-03-23 2023-03-23
HASH a25acc6c420a1bb0fdc9456b4834c1b4 2023-03-23 2023-03-23
URL http://hmcks.realma.r-e.kr/gl/e… 2023-03-23 2023-03-23
DOMAIN hmcks.realma.r-e.kr 2023-03-23 2023-03-23

Related Actors

Related Reports

« Back