Quick Overview of Babyshark Campaign disguise as Defense-themed HWP Document, involving the Kimsuky APT Group

2025-01-23 S2W

https://s2w.inc/en/resource/detail/751

Thumbnail for Quick Overview of Babyshark Campaign disguise as Defense-themed HWP Document, involving the Kimsuky APT Group

S2W analyzed a January 2025 phishing email that used a defense industry digital innovation seminar lure to deliver a malicious HWP document linked to Kimsuky Babyshark activity. The attachment embedded an OLE object that dropped files for persistence and contacted a C2 URL using the "comline" query pattern associated with prior Babyshark campaigns. The malware selectively delivered a final payload to specified targets, with earlier Babyshark cases showing QuasarRAT used for remote control and information theft.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.elmer.com.tr/module… 2025-01-23 2026-01-14
HASH 8a801a356d5a7b3235b920e4d36336d2 2025-01-23 2025-01-23

Related Actors

Related Reports

« Back