Kimsuky: A Continuous Threat to South Korea with Deceptive Tactics
ID: 379dfb03-7792-5fe9-aa66-d4b3946264b2
STIX ID: report--379dfb03-7792-5fe9-aa66-d4b3946264b2
Feed Name: Seqrite Blog
Seqrite Labs analyzed two Kimsuky campaigns targeting South Korean entities that use malicious .lnk attachments to fetch obfuscated VBScript which decodes embedded PDF/ZIP payloads; the resulting VBScript and PowerShell components implement persistence, browser and cryptocurrency-wallet data theft, keylogging, VM checks, and chunked exfiltration to C2 servers. The report provides technical disassembly of each stage, IoCs (hashes and C2 domains), and MITRE ATT&CK mappings for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
