Kimsuky Wanna Be Your Social Network Friend

2025-01-21 NSHC

https://jsac.jpcert.or.jp/archive/2025/pdf/JSAC2025_1_8_hankuk_sangyoon_jeonghee_en.pdf

Attachments

JSAC2025_1_8_hankuk_sangyoon_jeonghee_en.pdf (2 MB)

Thumbnail for Kimsuky Wanna Be Your Social Network Friend

NSHC's JSAC presentation describes a June 2024 Kimsuky social-engineering operation that used LinkedIn reconnaissance against Republic of Korea Navy-related personnel and then moved into spear phishing. The actors prepared VPS/VDS infrastructure, used mail that passed SPF, DKIM, ARC, and DMARC checks, and delivered Google Drive links to EGG archives to reduce attachment-scanning friction. Execution led to PE malware, with different PowerShell commands for EXE and DLL paths and regsvr32 used to trigger a DLL payload from ProgramData. The deck also notes RC4-encrypted data, fake PDF headers, and attacker infrastructure registration checks as part of the campaign's defense-evasion and resource-development tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN vamboo.n-e.kr 2025-01-21 2025-06-09
HASH 5bc6637eced9464fc22e6666a4eeb5b… 2025-01-21 2025-01-21
HASH 39b5e5ca7e8dfb1b446c793c1187609… 2025-01-21 2025-01-21
HASH d66c69b99e978727d5ffdf75ab0c969… 2025-01-21 2025-01-21
HASH d39b9fdeaa6336fedb63bcb1962a1a1… 2025-01-21 2025-01-21
HASH 66710f1e5fdfca8bbd4681e979bf421… 2025-01-21 2025-01-21
HASH f6d41367670803d3439fce5c7c7d882… 2025-01-21 2025-01-21
HASH fb17b8d46f75e9cb956972500312932… 2025-01-21 2025-01-21
HASH f16c81b9b5ff62ae8d82d717d835bf5… 2025-01-21 2025-01-21
DOMAIN proposalo.p-e.kr 2025-01-21 2025-01-21
IPv4 95.164.62.157 2024-06-07 2025-01-21

Related Actors

Related Reports

« Back