Kimsuky Arsenal Exposure: Multi-format Trojan Analysis

2024-11-20 Sec AI

https://www.secai.ai/blog/latest_research/Kimsuky_Arsenal_Exposure

Thumbnail for Kimsuky Arsenal Exposure: Multi-format Trojan Analysis

SecAI reported a 2024 Kimsuky campaign that used phishing websites to steal email credentials before sending follow-up phishing messages from more trusted accounts. The activity targeted South Korean diplomatic, construction, university, and security-themed victims with lures delivered as LNK, ISO, XLS, DOC, CHM, MSC, JS, and other Windows file formats. Embedded cmd, batch, VBS, JavaScript, and PowerShell stages downloaded, decrypted, or ran payloads that ultimately executed C2 commands. The report notes PHP-style URL patterns with meaningful parameters, date-like directory naming, Korean dynamic domains such as n-e.kr, p-e.kr, r-e.kr, o-r.kr, and kro.kr, and increasing use of free domains including site, store, online, me, and shop.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN o-r.kr 2023-05-24 2026-06-01
DOMAIN r-e.kr 2023-03-23 2026-06-01
DOMAIN n-e.kr 2022-08-26 2026-06-01
DOMAIN p-e.kr 2021-12-21 2026-06-01
HASH 7d766cbd60b2184b4181eb83562d5a4… 2024-11-20 2024-11-20
HASH 6263530f1bde08b13872252fa1e90ef… 2024-11-20 2024-11-20
HASH 5d25e53b59bd2dcf234c6819f8cd294… 2024-11-20 2024-11-20
HASH ea332de382c843e4d862323466fee3d… 2024-11-20 2024-11-20
HASH 1099a77b2de97f26605b32e25e806b6… 2024-11-20 2024-11-20
HASH 8028b918d06cf3635e7e77d29cb0a46… 2024-08-29 2024-11-20
HASH 06e2ab3fe5afc927642244644dfddb0… 2024-08-07 2024-11-20
HASH 30584f13c0a9d0c86562c803de35043… 2024-05-16 2024-11-20
HASH 35ddb63c0729a7e3019c026865ea195… 2024-02-22 2024-11-20

Related Actors

Related Reports

« Back