Kimsuky APT Targets South Korea with Deceptive PDF Lures
2025-04-04 • Seqrite •
https://www.seqrite.com/blog/kimsuky-apt-south-korea-pdf-lures/
Seqrite Labs links two South Korea-focused campaigns to Kimsuky, also known as Black Banshee, using government-themed PDF/LNK lures sent by email to government entities, local offices, and residential recipients. The infection chain begins with a malicious LNK that retrieves an obfuscated VBScript from external C2 infrastructure, drops a PDF and ZIP archive, and runs VBScript and PowerShell components hidden in files such as 1.vbs, 1.ps1, 1.log, and 2.log. The PowerShell stage collects the BIOS serial number, checks for virtualized environments, creates host-specific temporary storage, and supports data exfiltration, browser credential theft, cryptocurrency wallet file collection, persistence, and C2 communication. A decoded second log contains keylogging and clipboard-monitoring functionality, showing the campaign’s emphasis on credential and sensitive data theft from compromised South Korean systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 28f2fcece68822c38e72310c911ef00… | 2025-04-04 | 2025-06-17 |
| DOMAIN | srvdown.ddns.net | 2025-04-04 | 2025-06-17 |
| DOMAIN | cdn.glitch.global | 2025-03-28 | 2025-05-27 |
| HASH | 1b90eff0b4f54da72b19195489c3af6c | 2025-04-04 | 2025-04-04 |
| HASH | a3353ea094f45915408065d03ae157c4 | 2025-04-04 | 2025-04-04 |
| HASH | f0f63808e17994e91fd397e3a54a80cb | 2025-04-04 | 2025-04-04 |
| URL | http://srvdown.ddns.net | 2025-04-04 | 2025-04-04 |
| URL | https://cdn.glitch.global/ | 2025-04-04 | 2025-04-04 |
| HASH | 1d64508b384e928046887dd9cb32c2ac | 2025-03-28 | 2025-04-04 |
| HASH | ce4549607e46e656d8e019624d5036c1 | 2025-03-25 | 2025-04-04 |
| HASH | 64677cae14a2ec4d393a81548417b61b | 2025-03-25 | 2025-04-04 |