Kimsuky group's resume impersonation malware

2020-03-04 Tay

https://swanleesec.github.io/posts/%EC%95%85%EC%84%B1%EC%BD%94%EB%93%9C-%EA%B9%80%EC%88%98%ED%82%A4-%EC%A1%B0%EC%A7%81%EC%9D%98-%EC%9D%B4%EB%A0%A5%EC%84%9C-%EC%82%AC%EC%B9%AD-%EC%95%85%EC%84%B1%EC%BD%94%EB%93%9C

Thumbnail for Kimsuky group's resume impersonation malware

A malware analysis write-up describes a Kimsuky variant targeting South Korea with a resume-themed executable named like an HWP document, “resume form.hwp.scr,” built on 27 February 2020. Execution replaces the initial SCR with a decoy HWP resume form while dropping DLL/BAT components and an AutoUpdate.dll executable that performs the main malicious activity. The malware attempts C2 communication with suzuki.datastore.pe.hu at 45.13.135.103, downloads additional files with host metadata in URL parameters, registers AutoUpdate.dll for startup through regsvr32, and injects malicious code into explorer.exe. The behavior indicates a lure-driven Kimsuky infection chain focused on persistence, payload retrieval, and process injection after deceiving the user with a legitimate-looking resume document.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.13.135.103 2020-03-04 2021-06-01
DOMAIN suzuki.datastore.pe.hu 2020-03-04 2020-09-30
HASH 47c95f19ebd745d588bb208ff89c90ba 2020-03-04 2020-03-04
URL http://suzuki.datastore.pe.hu//… 2020-03-04 2020-03-04
URL http://suzuki.datastore.pe.hu 2020-03-04 2020-03-04

Related Actors

Related Reports

« Back