Operation KimsuKEE(Kimsuky Eternal Evolution)
2019-05-10 • Igloo •
https://www.igloo.co.kr/security-information/operation-kimsukeekimsuky-eternal-evolution/
Igloo analyzes Operation KimsuKEE as an evolved Kimsuky intrusion chain that still begins with an HWP document exploiting PostScript execution to load shellcode. The newer sample differs from earlier Kimsuky tradecraft by abusing the legitimate mshta.exe process, chaining multiple malware distribution URLs, and delivering fileless VBA and PowerShell scripts instead of relying mainly on Win32 API-based droppers or downloaders. The infection flow disables Word and Excel macro security settings, collects system and recent-file information with shell commands, Base64-encodes the results with certutil, and establishes persistence through a registry PowerShell command. The final payload, driving.ps1, is described as a fileless PowerShell keylogger, with related distribution and upload URLs under jmable.mireene.com and several hashes provided for detection. The report matters because it shows Kimsuky adapting toward script-heavy, fileless execution while retaining HWP exploitation and keylogging behavior that defenders can monitor.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://jmable.mireene.com/shop/… | 2019-05-10 | 2020-11-02 |
| DOMAIN | jmable.mireene.com | 2019-05-10 | 2020-11-02 |
| HASH | 98b68c2f2fdc67db371bb6783b811c8f | 2019-05-10 | 2019-11-18 |
| HASH | e0c5bf2cd4bec075f442323df79a526f | 2019-05-10 | 2019-05-10 |
| HASH | 9e49c982be9bda85980861c7f5b8493d | 2019-05-10 | 2019-05-10 |
| HASH | 92756ccc7c91b09b8b098e02c2f5aae6 | 2019-05-10 | 2019-05-10 |
| HASH | 617372010e9665cf8267f629e6d55fff | 2019-05-10 | 2019-05-10 |
| HASH | e9c1dec196441577816d85dc304d702d | 2019-05-10 | 2019-05-10 |
| URL | http://jmable.mireene.com/shop/… | 2019-05-10 | 2019-05-10 |
| URL | http://jmable.mireene.com/shop/… | 2019-05-10 | 2019-05-10 |
| URL | http://jmable.mireene.com/shop/… | 2019-05-10 | 2019-05-10 |
| URL | http://jmable.mireene.com/shop/… | 2019-05-10 | 2019-05-10 |
| URL | http://jmable.mireene.com/shop/… | 2019-05-10 | 2019-05-10 |
| URL | http://jmable.mireene.com/shop/… | 2019-05-10 | 2019-05-10 |
| IPv4 | 110.4.107.244 | 2019-05-10 | 2019-05-10 |