Kimsuky Targets South Korean Research Institutes with Fake Import Declaration

2023-11-30 Ahnlab

https://asec.ahnlab.com/en/59387/

Thumbnail for Kimsuky Targets South Korean Research Institutes with Fake Import Declaration

ASEC reports that Kimsuky distributed a malicious JSE file disguised as an import declaration to South Korean research institutes. The dropper contains obfuscated PowerShell, a Base64-encoded Nikidoor backdoor, and a decoy PDF that displays victim-specific content while the malware runs in the background. The backdoor is written into ProgramData, executed through rundll32.exe, copied as IconCache.db for persistence, and registered as a scheduled task named iconcache. It collects anti-malware, network, host, user, and OS information with commands such as wmic and ipconfig, encodes command output, and communicates with rscnode.dothome.co.kr endpoints for upload and command execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d6abeeb469e2417bbcd3c122c06ba099 2023-11-21 2024-03-05
HASH d2335df6d17fc7c2a5d0583423e39ff8 2023-11-21 2023-11-30
URL http://rscnode.dothome.co.kr/in… 2023-11-21 2023-11-30
URL http://rscnode.dothome.co.kr/up… 2023-11-21 2023-11-30
DOMAIN rscnode.dothome.co.kr 2023-11-21 2023-11-30

Related Actors

Related Reports

« Back