Kimsuky Targets South Korean Research Institutes with Fake Import Declaration
2023-11-30 • Ahnlab •
ASEC reports that Kimsuky distributed a malicious JSE file disguised as an import declaration to South Korean research institutes. The dropper contains obfuscated PowerShell, a Base64-encoded Nikidoor backdoor, and a decoy PDF that displays victim-specific content while the malware runs in the background. The backdoor is written into ProgramData, executed through rundll32.exe, copied as IconCache.db for persistence, and registered as a scheduled task named iconcache. It collects anti-malware, network, host, user, and OS information with commands such as wmic and ipconfig, encodes command output, and communicates with rscnode.dothome.co.kr endpoints for upload and command execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d6abeeb469e2417bbcd3c122c06ba099 | 2023-11-21 | 2024-03-05 |
| HASH | d2335df6d17fc7c2a5d0583423e39ff8 | 2023-11-21 | 2023-11-30 |
| URL | http://rscnode.dothome.co.kr/in… | 2023-11-21 | 2023-11-30 |
| URL | http://rscnode.dothome.co.kr/up… | 2023-11-21 | 2023-11-30 |
| DOMAIN | rscnode.dothome.co.kr | 2023-11-21 | 2023-11-30 |