Kimsuky APT Targets South Korea with Deceptive PDF Lures

2025-04-04 Seqrite

https://www.seqrite.com/blog/kimsuky-apt-south-korea-pdf-lures/

Thumbnail for Kimsuky APT Targets South Korea with Deceptive PDF Lures

Seqrite Labs links two South Korea-focused campaigns to Kimsuky, also known as Black Banshee, using government-themed PDF/LNK lures sent by email to government entities, local offices, and residential recipients. The infection chain begins with a malicious LNK that retrieves an obfuscated VBScript from external C2 infrastructure, drops a PDF and ZIP archive, and runs VBScript and PowerShell components hidden in files such as 1.vbs, 1.ps1, 1.log, and 2.log. The PowerShell stage collects the BIOS serial number, checks for virtualized environments, creates host-specific temporary storage, and supports data exfiltration, browser credential theft, cryptocurrency wallet file collection, persistence, and C2 communication. A decoded second log contains keylogging and clipboard-monitoring functionality, showing the campaign’s emphasis on credential and sensitive data theft from compromised South Korean systems.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 28f2fcece68822c38e72310c911ef00… 2025-04-04 2025-06-17
DOMAIN srvdown.ddns.net 2025-04-04 2025-06-17
DOMAIN cdn.glitch.global 2025-03-28 2025-05-27
HASH 1b90eff0b4f54da72b19195489c3af6c 2025-04-04 2025-04-04
HASH a3353ea094f45915408065d03ae157c4 2025-04-04 2025-04-04
HASH f0f63808e17994e91fd397e3a54a80cb 2025-04-04 2025-04-04
URL http://srvdown.ddns.net 2025-04-04 2025-04-04
URL https://cdn.glitch.global/ 2025-04-04 2025-04-04
HASH 1d64508b384e928046887dd9cb32c2ac 2025-03-28 2025-04-04
HASH ce4549607e46e656d8e019624d5036c1 2025-03-25 2025-04-04
HASH 64677cae14a2ec4d393a81548417b61b 2025-03-25 2025-04-04

Related Actors

Related Reports

2024-09-12 • 56% Match
#Kimsuky #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003
Shares tags: Kimsuky, T1082, T1140
2026-04-17 • 53% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, T1082, T1140
« Back