We Dumped a Live Kimsuky C2 and Recovered Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger
2026-04-11 • Break Glass Intelligence •
https://intel.breakglass.tech/post/kimsuky-chm-nidlog-c2-dump-full-payload-recovery
Breakglass analyzed a live Kimsuky C2 tied to a CHM-based intrusion chain after a MalwareBazaar submission exposed check.nid-log[.]com serving multiple payload stages. The chain uses hh.exe, PowerShell, certutil, and wscript to decode and execute VBScript that performs host reconnaissance, creates an "Edge Updater" scheduled task, and fetches later-stage code directly over HTTP. Recovered payloads include a PowerShell keylogger with keystroke capture, clipboard monitoring, active-window tracking, a Global\AlreadyRunning19122345 mutex, and timed multipart exfiltration to finalservice.php. The infrastructure retained the "Million OK !!!!" health-check signature seen in earlier Kimsuky reporting while moving across multiple VPS providers and 79 mapped domains, giving defenders concrete payload source, endpoints, and detection artifacts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d7c09e7bf79aa9b786dcd9f870427f4… | 2026-04-11 | 2026-04-17 |
| HASH | af50f35701916d3909f2727cdcbde1a… | 2026-04-11 | 2026-04-17 |
| HASH | 85f8f8a3f28d2956776fbbd0365cdb7… | 2026-04-11 | 2026-04-17 |
| HASH | a36576a096db24a1c91327eb547dedf… | 2026-04-11 | 2026-04-17 |
| HASH | 0ac44ad9cfbc58ed76415f7bc79239f9 | 2026-04-11 | 2026-04-17 |
| HASH | 1eff237dee95172363bfc0342d0389f… | 2026-04-11 | 2026-04-17 |
| URL | http://check.nid-log.com/api/fi… | 2026-04-11 | 2026-04-17 |
| URL | http://check.nid-log.com/api/bo… | 2026-04-11 | 2026-04-17 |
| URL | http://check.nid-log.com/api/ch… | 2026-04-11 | 2026-04-17 |
| DOMAIN | verify.efine-log.kro.kr | 2026-04-11 | 2026-04-17 |
| DOMAIN | udalyonka.com | 2026-04-11 | 2026-04-17 |
| DOMAIN | nid-htl.duckdns.org | 2026-04-11 | 2026-04-17 |
| DOMAIN | nid-log.com | 2026-04-11 | 2026-04-17 |
| DOMAIN | chk.uncork.biz | 2026-04-11 | 2026-04-17 |
| DOMAIN | nid-navertca.servehalflife.com | 2026-04-11 | 2026-04-17 |
| DOMAIN | nid-naverpep.servequake.com | 2026-04-11 | 2026-04-17 |
| DOMAIN | nid-naverfxc.servecounterstrike… | 2026-04-11 | 2026-04-17 |
| DOMAIN | uncork.biz | 2026-04-11 | 2026-04-17 |
| DOMAIN | nid-navercwu.servecounterstrike… | 2026-04-11 | 2026-04-17 |
| IPv4 | 27.102.137.38 | 2026-04-11 | 2026-04-17 |
| IPv4 | 38.60.220.135 | 2026-04-11 | 2026-04-17 |
| IPv4 | 27.102.138.45 | 2026-04-11 | 2026-04-17 |
| IPv4 | 51.79.185.184 | 2026-04-11 | 2026-04-17 |
| IPv4 | 130.94.29.111 | 2026-04-11 | 2026-04-17 |
| IPv4 | 27.102.137.150 | 2026-04-11 | 2026-04-17 |
| IPv4 | 162.255.119.150 | 2026-04-11 | 2026-04-17 |
| IPv4 | 118.194.249.109 | 2026-03-12 | 2026-04-17 |
| HASH | 4599ac1bbe483c73064df1353feafd01 | 2025-06-05 | 2026-04-17 |
| YARA | Kimsuky_Bootservice_CHM_Dropper | 2026-04-11 | 2026-04-11 |
| URL | http://check.nid-log.com/api/bo… | 2026-04-11 | 2026-04-11 |
| URL | http://check.nid-log.com/api | 2026-04-11 | 2026-04-11 |
| DOMAIN | withheldforprivacy.com | 2026-04-11 | 2026-04-11 |