logo

Kimsuky: A Continuous Threat to South Korea with Deceptive Tactics

ID: 379dfb03-7792-5fe9-aa66-d4b3946264b2

STIX ID: report--379dfb03-7792-5fe9-aa66-d4b3946264b2

Feed Name: Seqrite Blog

Threat Score
80/100

Date Published: 2025-04-04

Date Updated: 2026-04-30

Author: Dixit Panchal

...
...

Seqrite Labs analyzed two Kimsuky campaigns targeting South Korean entities that use malicious .lnk attachments to fetch obfuscated VBScript which decodes embedded PDF/ZIP payloads; the resulting VBScript and PowerShell components implement persistence, browser and cryptocurrency-wallet data theft, keylogging, VM checks, and chunked exfiltration to C2 servers. The report provides technical disassembly of each stage, IoCs (hashes and C2 domains), and MITRE ATT&CK mappings for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.