Kimsuky A Gift That Keeps on Giving

2024-09-17 somedieyoung ZZ

https://somedieyoungzz.github.io/posts/kimsuky-6/

Thumbnail for Kimsuky A Gift That Keeps on Giving

The analysis covers a Windows LNK sample whose TTPs are assessed by the author as consistent with Kimsuky or another DPRK-based actor. The shortcut uses mshta.exe and JavaScript arguments to reach 64.49.14.181, retrieve a Base64-encoded ZIP, write it as C:\ProgramData\t.zip, extract it, and run s.vbs. The VBScript uses obfuscation and a Caesar-style decoding routine, creates a scheduled task disguised as an Edge update, and opens a decoy DOCX from ProgramData. Later stages add Run-key persistence for a VBS file and execute PowerShell against C:\ProgramData\xM578.tmp, giving defenders concrete Windows persistence and staging behaviors to hunt.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 64.49.14.181 2024-09-17 2024-09-26
HASH 37fb639a295daa760c739bc21c553406 2024-09-17 2024-09-20
HASH 0c3fd7f45688d5ddb9f0107877ce2fbd 2024-09-17 2024-09-20
HASH 50e4d8a112e4aad2c984d22f83c80c8… 2024-09-17 2024-09-20
HASH 41cf6298a41c27357ee5f70d8cd1c0b… 2024-09-17 2024-09-20
HASH 622358469e5e24114dd0eb03da815576 2024-09-17 2024-09-17
HASH 4cbafb288263fe76f5e36f1f042be22d 2024-09-17 2024-09-17
HASH 73ed9b012785dc3b3ee33aa52700cfe4 2024-09-17 2024-09-17

Related Actors

Related Reports

« Back