Kimsuky A Gift That Keeps on Giving
2024-09-17 • somedieyoung ZZ •
The analysis covers a Windows LNK sample whose TTPs are assessed by the author as consistent with Kimsuky or another DPRK-based actor. The shortcut uses mshta.exe and JavaScript arguments to reach 64.49.14.181, retrieve a Base64-encoded ZIP, write it as C:\ProgramData\t.zip, extract it, and run s.vbs. The VBScript uses obfuscation and a Caesar-style decoding routine, creates a scheduled task disguised as an Edge update, and opens a decoy DOCX from ProgramData. Later stages add Run-key persistence for a VBS file and execute PowerShell against C:\ProgramData\xM578.tmp, giving defenders concrete Windows persistence and staging behaviors to hunt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 64.49.14.181 | 2024-09-17 | 2024-09-26 |
| HASH | 37fb639a295daa760c739bc21c553406 | 2024-09-17 | 2024-09-20 |
| HASH | 0c3fd7f45688d5ddb9f0107877ce2fbd | 2024-09-17 | 2024-09-20 |
| HASH | 50e4d8a112e4aad2c984d22f83c80c8… | 2024-09-17 | 2024-09-20 |
| HASH | 41cf6298a41c27357ee5f70d8cd1c0b… | 2024-09-17 | 2024-09-20 |
| HASH | 622358469e5e24114dd0eb03da815576 | 2024-09-17 | 2024-09-17 |
| HASH | 4cbafb288263fe76f5e36f1f042be22d | 2024-09-17 | 2024-09-17 |
| HASH | 73ed9b012785dc3b3ee33aa52700cfe4 | 2024-09-17 | 2024-09-17 |