Kimsuky group appears to be exploiting OneNote like the cybercrime group

2023-03-17 S2W

https://medium.com/s2wblog/kimsuky-group-appears-to-be-exploiting-onenote-like-the-cybercrime-group-3c96b0b85b9f

Thumbnail for Kimsuky group appears to be exploiting OneNote like the cybercrime group

S2W reported that Kimsuky was distributing malware with a malicious Microsoft OneNote file, a delivery technique more commonly seen in cybercrime campaigns. The lure impersonated Korea University’s Institute for Peace and Democracy and asked survey participants to open what appeared to be a privacy-agreement HWP file for recompense, but clicking the embedded object executed hidden VBS. The script attempted to download a decoy HWP and additional code from delps.scienceontheweb.net, using a list.php?query=1 URL pattern and hosting infrastructure previously associated with Kimsuky Babyshark activity. The final payload was not recovered, but the recompense theme, URL format, and 185.176.43[.]98 infrastructure supported the report’s Kimsuky attribution.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN delps.scienceontheweb.net 2023-03-17 2024-12-16
IPv4 185.176.43.98 2020-09-04 2024-12-16
HASH aa756b20170aa0869d6f5d5b5f1b7c37 2023-03-17 2023-05-24
HASH f2a0e92b80928830704a00c91df87644 2023-03-17 2023-05-24
URL http://delps.scienceontheweb.ne… 2023-03-17 2023-03-20
URL http://delps.scienceontheweb.ne… 2023-03-17 2023-03-20

Related Actors

Related Reports

« Back