Quick Overview of Babyshark Campaign disguise as Defense-themed HWP Document, involving the Kimsuky APT Group
2025-01-23 • S2W •
S2W analyzed a January 2025 phishing email that used a defense industry digital innovation seminar lure to deliver a malicious HWP document linked to Kimsuky Babyshark activity. The attachment embedded an OLE object that dropped files for persistence and contacted a C2 URL using the "comline" query pattern associated with prior Babyshark campaigns. The malware selectively delivered a final payload to specified targets, with earlier Babyshark cases showing QuasarRAT used for remote control and information theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.elmer.com.tr/module… | 2025-01-23 | 2026-01-14 |
| HASH | 8a801a356d5a7b3235b920e4d36336d2 | 2025-01-23 | 2025-01-23 |
Related Actors
Related Reports
Shares tags: Kimsuky, BabyShark • Same author: S2W • Published within a week
Shares tag: Kimsuky • Shares 1 IOC • Published within a week
Shares tags: Kimsuky, BabyShark • Same author: S2W
Shares tags: Kimsuky, BabyShark • Same author: S2W
Shares tags: Kimsuky, BabyShark
Shares tags: Kimsuky, BabyShark