Kimsuky is targeting an arms manufacturer in Europe

2024-06-07 Dimitribest

https://www.linkedin.com/pulse/kimsuky-targeting-arms-manufacturer-europe-dmitry-melikov-dquge/

Thumbnail for Kimsuky is targeting an arms manufacturer in Europe

Kimsuky was assessed with high confidence as targeting a western European weapons-component manufacturer through spear-phishing emails using a General Dynamics job-description lure. The malicious attachment, Safety Manager JD (General Dynamics HR Division II).jse, decoded two Base64 blocks to show a benign PDF while silently launching an executable library described as a new espionage tool. The payload created persistence through a CacheDB service and the Windows Run registry key, registered victims with a unique identifier, sent system data to C2, and supported file enumeration, process-path collection, screenshots, socket checks, process execution, secondary payload download, sleep, and self-removal. Network infrastructure included download.uberlingen[.]com and related domains resolving to 94.131.120[.]80, with overlap around *.r-e[.]kr cited as supporting Kimsuky infrastructure links. The targeting of a defense supply-chain manufacturer highlights continued North Korean interest in military and aerospace-related organizations.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN r-e.kr 2023-03-23 2026-06-01
HASH 8346d90508b5d41d151b7098c7a3e868 2024-06-07 2025-06-09
HASH 537806c02659a12c5b21efa51b2322c1 2024-06-07 2025-06-09
DOMAIN download.uberlingen.com 2024-06-07 2025-06-09
IPv4 95.164.62.157 2024-06-07 2025-01-21
DOMAIN online.viewers.r-e.kr 2024-06-07 2024-08-24
DOMAIN share.dihl-defence.o-r.kr 2024-06-07 2024-08-24
DOMAIN cloud.adoubleu.de 2024-06-07 2024-08-24
DOMAIN ecloud.uberlingen.n-e.kr 2024-06-07 2024-08-24
DOMAIN share-defence.verymad.net 2024-06-07 2024-08-24
DOMAIN share-defence.ohbah.com 2024-06-07 2024-08-24
URL http://download.uberlingen.com/… 2024-06-07 2024-06-20
DOMAIN share-defence.uberlingen.com 2024-06-07 2024-06-20
IPv4 94.131.120.80 2024-06-07 2024-06-20
HASH 6e5d5a8d06452852f1ccbc9b6dbab3eb 2024-06-07 2024-06-19
HASH f58a9905aad4d82a89a787017f1a357… 2024-06-07 2024-06-19
HASH 3314b6ea393e180c20db52448ab6980… 2024-06-07 2024-06-19
HASH 24a42a912c6ad98ab3910cb1e031edb… 2024-06-07 2024-06-19
YARA Kimsuky_Spy_Tool 2024-06-07 2024-06-07
DOMAIN qntks.shadir.com 2024-06-07 2024-06-07
DOMAIN nero1.r-e.kr 2024-06-07 2024-06-07
DOMAIN logo.kalbas.com 2024-06-07 2024-06-07
DOMAIN accounts.login.idm.uberlingen.c… 2024-06-07 2024-06-07
DOMAIN de.uberlingen.com 2024-06-07 2024-06-07
DOMAIN news.uberlingen.com 2024-06-07 2024-06-07
IPv4 94.131.9.51 2024-06-07 2024-06-07
IPv4 103.113.70.148 2024-06-07 2024-06-07

Related Actors

Related Reports

« Back