Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit

2023-05-23 Sentinel One

https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/

Thumbnail for Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit

SentinelLabs attributes an ongoing campaign to Kimsuky targeting North Korea-focused information services, human rights activists, and DPRK-defector support organizations. The campaign uses Korean phishing emails from Daum accounts and password-protected archives containing CHM lure files themed around difficulties faced by North Korean human rights organizations. The CHM files create and persist VBScript payloads, then contact C2 URLs such as file.com-port.space to retrieve a VBScript RandomQuery variant focused on system profiling, file enumeration, process listing, and exfiltration. RandomQuery collects hardware, operating system, Desktop, Documents, Favorites, Recent, Program Files, Downloads, and process data, Base64-encodes it, and posts it back to overlapping C2 infrastructure. The activity shows Kimsuky continuing to use CHM delivery and tailored reconnaissance tooling while registering deceptive domains under less common TLDs such as .online and .click.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 49c70c292a634e822300c57305698b5… 2023-05-23 2023-11-01
HASH 912f875899dd989fbfd64b515060f27… 2023-05-23 2023-05-23
HASH 84398dcd52348eec37738b27af9682a… 2023-05-23 2023-05-23
HASH 96d29a2d554b36d6fb7373ae5276585… 2023-05-23 2023-05-23
HASH 0288140be88bc3156b692db2516e38f… 2023-05-23 2023-05-23
HASH 8f2e6719ce0f29c2c6dbabe5a7bda59… 2023-05-23 2023-05-23

Related Actors

Related Reports

« Back