Kimsuky is targeting an arms manufacturer in Europe
2024-06-07 • Dimitribest •
https://www.linkedin.com/pulse/kimsuky-targeting-arms-manufacturer-europe-dmitry-melikov-dquge/
Kimsuky was assessed with high confidence as targeting a western European weapons-component manufacturer through spear-phishing emails using a General Dynamics job-description lure. The malicious attachment, Safety Manager JD (General Dynamics HR Division II).jse, decoded two Base64 blocks to show a benign PDF while silently launching an executable library described as a new espionage tool. The payload created persistence through a CacheDB service and the Windows Run registry key, registered victims with a unique identifier, sent system data to C2, and supported file enumeration, process-path collection, screenshots, socket checks, process execution, secondary payload download, sleep, and self-removal. Network infrastructure included download.uberlingen[.]com and related domains resolving to 94.131.120[.]80, with overlap around *.r-e[.]kr cited as supporting Kimsuky infrastructure links. The targeting of a defense supply-chain manufacturer highlights continued North Korean interest in military and aerospace-related organizations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | r-e.kr | 2023-03-23 | 2026-06-01 |
| HASH | 8346d90508b5d41d151b7098c7a3e868 | 2024-06-07 | 2025-06-09 |
| HASH | 537806c02659a12c5b21efa51b2322c1 | 2024-06-07 | 2025-06-09 |
| DOMAIN | download.uberlingen.com | 2024-06-07 | 2025-06-09 |
| IPv4 | 95.164.62.157 | 2024-06-07 | 2025-01-21 |
| DOMAIN | online.viewers.r-e.kr | 2024-06-07 | 2024-08-24 |
| DOMAIN | share.dihl-defence.o-r.kr | 2024-06-07 | 2024-08-24 |
| DOMAIN | cloud.adoubleu.de | 2024-06-07 | 2024-08-24 |
| DOMAIN | ecloud.uberlingen.n-e.kr | 2024-06-07 | 2024-08-24 |
| DOMAIN | share-defence.verymad.net | 2024-06-07 | 2024-08-24 |
| DOMAIN | share-defence.ohbah.com | 2024-06-07 | 2024-08-24 |
| URL | http://download.uberlingen.com/… | 2024-06-07 | 2024-06-20 |
| DOMAIN | share-defence.uberlingen.com | 2024-06-07 | 2024-06-20 |
| IPv4 | 94.131.120.80 | 2024-06-07 | 2024-06-20 |
| HASH | 6e5d5a8d06452852f1ccbc9b6dbab3eb | 2024-06-07 | 2024-06-19 |
| HASH | f58a9905aad4d82a89a787017f1a357… | 2024-06-07 | 2024-06-19 |
| HASH | 3314b6ea393e180c20db52448ab6980… | 2024-06-07 | 2024-06-19 |
| HASH | 24a42a912c6ad98ab3910cb1e031edb… | 2024-06-07 | 2024-06-19 |
| YARA | Kimsuky_Spy_Tool | 2024-06-07 | 2024-06-07 |
| DOMAIN | qntks.shadir.com | 2024-06-07 | 2024-06-07 |
| DOMAIN | nero1.r-e.kr | 2024-06-07 | 2024-06-07 |
| DOMAIN | logo.kalbas.com | 2024-06-07 | 2024-06-07 |
| DOMAIN | accounts.login.idm.uberlingen.c… | 2024-06-07 | 2024-06-07 |
| DOMAIN | de.uberlingen.com | 2024-06-07 | 2024-06-07 |
| DOMAIN | news.uberlingen.com | 2024-06-07 | 2024-06-07 |
| IPv4 | 94.131.9.51 | 2024-06-07 | 2024-06-07 |
| IPv4 | 103.113.70.148 | 2024-06-07 | 2024-06-07 |