Kimsuky group appears to be exploiting OneNote like the cybercrime group
2023-03-17 • S2W •
S2W reported that Kimsuky was distributing malware with a malicious Microsoft OneNote file, a delivery technique more commonly seen in cybercrime campaigns. The lure impersonated Korea University’s Institute for Peace and Democracy and asked survey participants to open what appeared to be a privacy-agreement HWP file for recompense, but clicking the embedded object executed hidden VBS. The script attempted to download a decoy HWP and additional code from delps.scienceontheweb.net, using a list.php?query=1 URL pattern and hosting infrastructure previously associated with Kimsuky Babyshark activity. The final payload was not recovered, but the recompense theme, URL format, and 185.176.43[.]98 infrastructure supported the report’s Kimsuky attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | delps.scienceontheweb.net | 2023-03-17 | 2024-12-16 |
| IPv4 | 185.176.43.98 | 2020-09-04 | 2024-12-16 |
| HASH | aa756b20170aa0869d6f5d5b5f1b7c37 | 2023-03-17 | 2023-05-24 |
| HASH | f2a0e92b80928830704a00c91df87644 | 2023-03-17 | 2023-05-24 |
| URL | http://delps.scienceontheweb.ne… | 2023-03-17 | 2023-03-20 |
| URL | http://delps.scienceontheweb.ne… | 2023-03-17 | 2023-03-20 |