Kimsuky APT 组织钓鱼样本分析

2026-04-07 Sad Sec Analysis of a Kimsuky APT Phishing Sample

https://sadsec.com/redteaming/ir-dprk-apt-phishing/

Thumbnail for Kimsuky APT 组织钓鱼样本分析

A suspected Kimsuky phishing operation used a Korean Army K-ICTC themed lure to target military, defense, diplomacy, and related research audiences. The victim-facing archive contained a convincing invitation PDF and a PDF-disguised LNK shortcut that downloaded an encoded VBE loader from 103.67.196.25, then used PowerShell, getmac-derived host identification, and an AppleSeed-style `type=apple` C2 parameter. Persistence was created through a `Chrome_Update` scheduled task running `wscript.exe /b ant.vbe` from `C:\Users\Public\Music`, with later commands delivered after an observation period. The second stage abused legitimate Chrome Remote Desktop components, a fixed PIN, and a CMSTPLUA UAC bypass script to establish covert remote access, showing a staged intrusion that blends script-based loading with legitimate remote administration tooling.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 103.67.196.25 2026-04-07 2026-05-19

Related Actors

Related Reports

2026-04-17 • 60% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tag: Kimsuky • Published within a month
« Back