We Dumped a Live Kimsuky C2 and Recovered Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger

2026-04-11 Break Glass Intelligence

https://intel.breakglass.tech/post/kimsuky-chm-nidlog-c2-dump-full-payload-recovery

Thumbnail for We Dumped a Live Kimsuky C2 and Recovered Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger

Breakglass analyzed a live Kimsuky C2 tied to a CHM-based intrusion chain after a MalwareBazaar submission exposed check.nid-log[.]com serving multiple payload stages. The chain uses hh.exe, PowerShell, certutil, and wscript to decode and execute VBScript that performs host reconnaissance, creates an "Edge Updater" scheduled task, and fetches later-stage code directly over HTTP. Recovered payloads include a PowerShell keylogger with keystroke capture, clipboard monitoring, active-window tracking, a Global\AlreadyRunning19122345 mutex, and timed multipart exfiltration to finalservice.php. The infrastructure retained the "Million OK !!!!" health-check signature seen in earlier Kimsuky reporting while moving across multiple VPS providers and 79 mapped domains, giving defenders concrete payload source, endpoints, and detection artifacts.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d7c09e7bf79aa9b786dcd9f870427f4… 2026-04-11 2026-04-17
HASH af50f35701916d3909f2727cdcbde1a… 2026-04-11 2026-04-17
HASH 85f8f8a3f28d2956776fbbd0365cdb7… 2026-04-11 2026-04-17
HASH a36576a096db24a1c91327eb547dedf… 2026-04-11 2026-04-17
HASH 0ac44ad9cfbc58ed76415f7bc79239f9 2026-04-11 2026-04-17
HASH 1eff237dee95172363bfc0342d0389f… 2026-04-11 2026-04-17
URL http://check.nid-log.com/api/fi… 2026-04-11 2026-04-17
URL http://check.nid-log.com/api/bo… 2026-04-11 2026-04-17
URL http://check.nid-log.com/api/ch… 2026-04-11 2026-04-17
DOMAIN verify.efine-log.kro.kr 2026-04-11 2026-04-17
DOMAIN udalyonka.com 2026-04-11 2026-04-17
DOMAIN nid-htl.duckdns.org 2026-04-11 2026-04-17
DOMAIN nid-log.com 2026-04-11 2026-04-17
DOMAIN chk.uncork.biz 2026-04-11 2026-04-17
DOMAIN nid-navertca.servehalflife.com 2026-04-11 2026-04-17
DOMAIN nid-naverpep.servequake.com 2026-04-11 2026-04-17
DOMAIN nid-naverfxc.servecounterstrike… 2026-04-11 2026-04-17
DOMAIN uncork.biz 2026-04-11 2026-04-17
DOMAIN nid-navercwu.servecounterstrike… 2026-04-11 2026-04-17
IPv4 27.102.137.38 2026-04-11 2026-04-17
IPv4 38.60.220.135 2026-04-11 2026-04-17
IPv4 27.102.138.45 2026-04-11 2026-04-17
IPv4 51.79.185.184 2026-04-11 2026-04-17
IPv4 130.94.29.111 2026-04-11 2026-04-17
IPv4 27.102.137.150 2026-04-11 2026-04-17
IPv4 162.255.119.150 2026-04-11 2026-04-17
IPv4 118.194.249.109 2026-03-12 2026-04-17
HASH 4599ac1bbe483c73064df1353feafd01 2025-06-05 2026-04-17
YARA Kimsuky_Bootservice_CHM_Dropper 2026-04-11 2026-04-11
URL http://check.nid-log.com/api/bo… 2026-04-11 2026-04-11
URL http://check.nid-log.com/api 2026-04-11 2026-04-11
DOMAIN withheldforprivacy.com 2026-04-11 2026-04-11

Related Actors

Related Reports

2026-04-17 • 100% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, T1082, T1140 • Shares 28 IOCs • Same author: Break Glass Intelligence • Published within a week
2024-09-12 • 51% Match
#Kimsuky #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003
Shares tags: Kimsuky, T1082, T1140
« Back