More Kimsuky “AutoUpdate” Malware

2020-06-25 Threatconnect

https://web.archive.org/web/20210412184505/https://threatconnect.com/blog/threatconnect-kimsuky-autoupdate-malware-research-roundup/

Thumbnail for More Kimsuky “AutoUpdate” Malware

ThreatConnect identified an additional malware sample likely associated with Kimsuky, a DPRK-based group, because its behavior matched earlier AutoUpdate-linked activity. The sample shared a string deobfuscation routine and specific URL-parameter behavior with a previously reported downloader. It was uploaded to VirusTotal as bmail-security-check.scr, and its embedded command-and-control server was security-confirm.bmail-org[.]com, which ThreatConnect observed as live on June 18, 2020. The finding helps defenders connect related Kimsuky malware variants and prioritize detections around downloader behavior, obfuscated C2 configuration, and suspicious security-themed lure filenames.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1e14ded758c5dd7b41fe20297935eeef 2020-06-25 2020-06-25
EMAIL [email protected] 2020-06-25 2020-06-25
URL http://www.fireeye.fr/blog/thre… 2020-06-25 2020-06-25
URL https://paste.cryptolaemus.com/… 2020-06-25 2020-06-25
DOMAIN security-confirm.bmail-org.com 2020-06-25 2020-06-25
HASH c315de8ac15b51163a3bc075063a58aa 2020-01-23 2020-06-25

Related Actors

Related Reports

« Back