Operation KimsuKEE(Kimsuky Eternal Evolution)

2019-05-10 Igloo

https://www.igloo.co.kr/security-information/operation-kimsukeekimsuky-eternal-evolution/

Igloo analyzes Operation KimsuKEE as an evolved Kimsuky intrusion chain that still begins with an HWP document exploiting PostScript execution to load shellcode. The newer sample differs from earlier Kimsuky tradecraft by abusing the legitimate mshta.exe process, chaining multiple malware distribution URLs, and delivering fileless VBA and PowerShell scripts instead of relying mainly on Win32 API-based droppers or downloaders. The infection flow disables Word and Excel macro security settings, collects system and recent-file information with shell commands, Base64-encodes the results with certutil, and establishes persistence through a registry PowerShell command. The final payload, driving.ps1, is described as a fileless PowerShell keylogger, with related distribution and upload URLs under jmable.mireene.com and several hashes provided for detection. The report matters because it shows Kimsuky adapting toward script-heavy, fileless execution while retaining HWP exploitation and keylogging behavior that defenders can monitor.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://jmable.mireene.com/shop/… 2019-05-10 2020-11-02
DOMAIN jmable.mireene.com 2019-05-10 2020-11-02
HASH 98b68c2f2fdc67db371bb6783b811c8f 2019-05-10 2019-11-18
HASH e0c5bf2cd4bec075f442323df79a526f 2019-05-10 2019-05-10
HASH 9e49c982be9bda85980861c7f5b8493d 2019-05-10 2019-05-10
HASH 92756ccc7c91b09b8b098e02c2f5aae6 2019-05-10 2019-05-10
HASH 617372010e9665cf8267f629e6d55fff 2019-05-10 2019-05-10
HASH e9c1dec196441577816d85dc304d702d 2019-05-10 2019-05-10
URL http://jmable.mireene.com/shop/… 2019-05-10 2019-05-10
URL http://jmable.mireene.com/shop/… 2019-05-10 2019-05-10
URL http://jmable.mireene.com/shop/… 2019-05-10 2019-05-10
URL http://jmable.mireene.com/shop/… 2019-05-10 2019-05-10
URL http://jmable.mireene.com/shop/… 2019-05-10 2019-05-10
URL http://jmable.mireene.com/shop/… 2019-05-10 2019-05-10
IPv4 110.4.107.244 2019-05-10 2019-05-10

Related Actors

Related Reports

« Back