Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit
2023-05-23 • Sentinel One •
https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/
SentinelLabs attributes an ongoing campaign to Kimsuky targeting North Korea-focused information services, human rights activists, and DPRK-defector support organizations. The campaign uses Korean phishing emails from Daum accounts and password-protected archives containing CHM lure files themed around difficulties faced by North Korean human rights organizations. The CHM files create and persist VBScript payloads, then contact C2 URLs such as file.com-port.space to retrieve a VBScript RandomQuery variant focused on system profiling, file enumeration, process listing, and exfiltration. RandomQuery collects hardware, operating system, Desktop, Documents, Favorites, Recent, Program Files, Downloads, and process data, Base64-encodes it, and posts it back to overlapping C2 infrastructure. The activity shows Kimsuky continuing to use CHM delivery and tailored reconnaissance tooling while registering deceptive domains under less common TLDs such as .online and .click.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 49c70c292a634e822300c57305698b5… | 2023-05-23 | 2023-11-01 |
| HASH | 912f875899dd989fbfd64b515060f27… | 2023-05-23 | 2023-05-23 |
| HASH | 84398dcd52348eec37738b27af9682a… | 2023-05-23 | 2023-05-23 |
| HASH | 96d29a2d554b36d6fb7373ae5276585… | 2023-05-23 | 2023-05-23 |
| HASH | 0288140be88bc3156b692db2516e38f… | 2023-05-23 | 2023-05-23 |
| HASH | 8f2e6719ce0f29c2c6dbabe5a7bda59… | 2023-05-23 | 2023-05-23 |