Kimsuky Wanna Be Your Social Network Friend
2025-01-21 • NSHC •
https://jsac.jpcert.or.jp/archive/2025/pdf/JSAC2025_1_8_hankuk_sangyoon_jeonghee_en.pdf
Attachments
NSHC's JSAC presentation describes a June 2024 Kimsuky social-engineering operation that used LinkedIn reconnaissance against Republic of Korea Navy-related personnel and then moved into spear phishing. The actors prepared VPS/VDS infrastructure, used mail that passed SPF, DKIM, ARC, and DMARC checks, and delivered Google Drive links to EGG archives to reduce attachment-scanning friction. Execution led to PE malware, with different PowerShell commands for EXE and DLL paths and regsvr32 used to trigger a DLL payload from ProgramData. The deck also notes RC4-encrypted data, fake PDF headers, and attacker infrastructure registration checks as part of the campaign's defense-evasion and resource-development tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | vamboo.n-e.kr | 2025-01-21 | 2025-06-09 |
| HASH | 5bc6637eced9464fc22e6666a4eeb5b… | 2025-01-21 | 2025-01-21 |
| HASH | 39b5e5ca7e8dfb1b446c793c1187609… | 2025-01-21 | 2025-01-21 |
| HASH | d66c69b99e978727d5ffdf75ab0c969… | 2025-01-21 | 2025-01-21 |
| HASH | d39b9fdeaa6336fedb63bcb1962a1a1… | 2025-01-21 | 2025-01-21 |
| HASH | 66710f1e5fdfca8bbd4681e979bf421… | 2025-01-21 | 2025-01-21 |
| HASH | f6d41367670803d3439fce5c7c7d882… | 2025-01-21 | 2025-01-21 |
| HASH | fb17b8d46f75e9cb956972500312932… | 2025-01-21 | 2025-01-21 |
| HASH | f16c81b9b5ff62ae8d82d717d835bf5… | 2025-01-21 | 2025-01-21 |
| DOMAIN | proposalo.p-e.kr | 2025-01-21 | 2025-01-21 |
| IPv4 | 95.164.62.157 | 2024-06-07 | 2025-01-21 |