Kimsuky Arsenal Exposure: Multi-format Trojan Analysis
2024-11-20 • Sec AI •
https://www.secai.ai/blog/latest_research/Kimsuky_Arsenal_Exposure
SecAI reported a 2024 Kimsuky campaign that used phishing websites to steal email credentials before sending follow-up phishing messages from more trusted accounts. The activity targeted South Korean diplomatic, construction, university, and security-themed victims with lures delivered as LNK, ISO, XLS, DOC, CHM, MSC, JS, and other Windows file formats. Embedded cmd, batch, VBS, JavaScript, and PowerShell stages downloaded, decrypted, or ran payloads that ultimately executed C2 commands. The report notes PHP-style URL patterns with meaningful parameters, date-like directory naming, Korean dynamic domains such as n-e.kr, p-e.kr, r-e.kr, o-r.kr, and kro.kr, and increasing use of free domains including site, store, online, me, and shop.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | o-r.kr | 2023-05-24 | 2026-06-01 |
| DOMAIN | r-e.kr | 2023-03-23 | 2026-06-01 |
| DOMAIN | n-e.kr | 2022-08-26 | 2026-06-01 |
| DOMAIN | p-e.kr | 2021-12-21 | 2026-06-01 |
| HASH | 7d766cbd60b2184b4181eb83562d5a4… | 2024-11-20 | 2024-11-20 |
| HASH | 6263530f1bde08b13872252fa1e90ef… | 2024-11-20 | 2024-11-20 |
| HASH | 5d25e53b59bd2dcf234c6819f8cd294… | 2024-11-20 | 2024-11-20 |
| HASH | ea332de382c843e4d862323466fee3d… | 2024-11-20 | 2024-11-20 |
| HASH | 1099a77b2de97f26605b32e25e806b6… | 2024-11-20 | 2024-11-20 |
| HASH | 8028b918d06cf3635e7e77d29cb0a46… | 2024-08-29 | 2024-11-20 |
| HASH | 06e2ab3fe5afc927642244644dfddb0… | 2024-08-07 | 2024-11-20 |
| HASH | 30584f13c0a9d0c86562c803de35043… | 2024-05-16 | 2024-11-20 |
| HASH | 35ddb63c0729a7e3019c026865ea195… | 2024-02-22 | 2024-11-20 |