Sample Analysis of Kimsuky's Attacks - iso
2024-12-18 • Sec AI •
https://www.secai.ai/blog/latest_research/Sample-Analysis-of-Kimsuky's-Attacks-iso
SecAI analyzed a Kimsuky ISO lure that masqueraded as RapportSetup and executed a malicious LNK and BAT script while also launching IBM Trusteer-branded legitimate software as cover. The BAT script checked for Avast and Kaspersky processes, then used curl to download follow-on content from trusteer.ink URLs, including a macro-associated payload path and C2 infrastructure that mimicked IBM Trusteer. The source links the sample to Kimsuky activity seen in 2024 against South Korean and allied targets, including embassy, construction, and university-themed lures used for information theft and remote control.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 296650b7faefae250ba871f043551b91 | 2024-12-18 | 2024-12-18 |