Kimsuky: Infamous Threat Actor Churns Out More Advanced Malware
2023-04-19 • Zimperium •
https://www.zimperium.com/blog/kimsuky-infamous-threat-actor-churns-out-more-advanced-malware/
This actor, also known by Thalium and APT37, has been active since 2012 and has produced several campaigns using various techniques, from watering hole attacks to spear phishing and malware campaigns targeting different platforms, including Android and Chromium-based browsers. The latest campaign described uses different methods: - Spear Phishing Attack: The campaign uses highly targeted emails to compromise either the ultimate victim or someone in their circle and use it to perform further spear phishing attacks. These apps are distributed using a feature called “internal testing,” which allows the app developers to distribute their apps to a small group of users flagged as “trusted.” The number of trusted users is very limited, which shows that this campaign is highly targeted. This organization was detected targeting Korean and German entities, and it’s believed that the main goal is to target government employees, military, manufacturing, academic, and the think tank of global diplomacy and security.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | navernnail.com | 2022-10-25 | 2026-01-14 |
| DOMAIN | lowerp.onlinewebshop.net | 2023-04-19 | 2023-11-01 |
| DOMAIN | mc.pzs.kr | 2022-05-18 | 2023-11-01 |
| DOMAIN | gonamod.com | 2022-08-24 | 2023-05-16 |
| IPv4 | 23.102.122.16 | 2023-04-19 | 2023-04-19 |
| HASH | 04bb7e1a0b4f830ed7d1377a394bc717 | 2023-03-20 | 2023-04-19 |
| HASH | 89f97e1d68e274b03bc40f6e06e2ba9a | 2022-10-25 | 2023-04-19 |
| HASH | 3458daa0dffdc3fbb5c931f25d7a1ec0 | 2022-10-25 | 2023-04-19 |
| DOMAIN | siekis.com | 2022-08-24 | 2023-04-19 |