Sample Analysis of Kimsuky's Attacks - iso

2024-12-18 Sec AI

https://www.secai.ai/blog/latest_research/Sample-Analysis-of-Kimsuky's-Attacks-iso

SecAI analyzed a Kimsuky ISO lure that masqueraded as RapportSetup and executed a malicious LNK and BAT script while also launching IBM Trusteer-branded legitimate software as cover. The BAT script checked for Avast and Kaspersky processes, then used curl to download follow-on content from trusteer.ink URLs, including a macro-associated payload path and C2 infrastructure that mimicked IBM Trusteer. The source links the sample to Kimsuky activity seen in 2024 against South Korean and allied targets, including embassy, construction, and university-themed lures used for information theft and remote control.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 296650b7faefae250ba871f043551b91 2024-12-18 2024-12-18

Related Actors

Related Reports

« Back