Kimsuky: Infamous Threat Actor Churns Out More Advanced Malware

2023-04-19 Zimperium

https://www.zimperium.com/blog/kimsuky-infamous-threat-actor-churns-out-more-advanced-malware/

Thumbnail for Kimsuky: Infamous Threat Actor Churns Out More Advanced Malware

This actor, also known by Thalium and APT37, has been active since 2012 and has produced several campaigns using various techniques, from watering hole attacks to spear phishing and malware campaigns targeting different platforms, including Android and Chromium-based browsers. The latest campaign described uses different methods: - Spear Phishing Attack: The campaign uses highly targeted emails to compromise either the ultimate victim or someone in their circle and use it to perform further spear phishing attacks. These apps are distributed using a feature called “internal testing,” which allows the app developers to distribute their apps to a small group of users flagged as “trusted.” The number of trusted users is very limited, which shows that this campaign is highly targeted. This organization was detected targeting Korean and German entities, and it’s believed that the main goal is to target government employees, military, manufacturing, academic, and the think tank of global diplomacy and security.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN navernnail.com 2022-10-25 2026-01-14
DOMAIN lowerp.onlinewebshop.net 2023-04-19 2023-11-01
DOMAIN mc.pzs.kr 2022-05-18 2023-11-01
DOMAIN gonamod.com 2022-08-24 2023-05-16
IPv4 23.102.122.16 2023-04-19 2023-04-19
HASH 04bb7e1a0b4f830ed7d1377a394bc717 2023-03-20 2023-04-19
HASH 89f97e1d68e274b03bc40f6e06e2ba9a 2022-10-25 2023-04-19
HASH 3458daa0dffdc3fbb5c931f25d7a1ec0 2022-10-25 2023-04-19
DOMAIN siekis.com 2022-08-24 2023-04-19

Related Actors

Related Reports

« Back