North Korean Hackers Attacking Drug Companies to Deploy Malware Via Weaponized Excel Files
ID: 63268059-eb2c-55b6-9fe3-4de22acbac31
STIX ID: report--63268059-eb2c-55b6-9fe3-4de22acbac31
Feed Name: cybersecurityNews.com
Kimsuky, a North Korean state-sponsored APT, is conducting a targeted campaign against pharmaceutical firms using a malicious shortcut named "White Life Science ERP Specification.lnk" that bundles a decoy Excel file, PowerShell, JavaScript, and a Task Scheduler XML. The attack uses 32-bit PowerShell via SysWOW64 to evade detection, drops payloads to C:\sysconfigs, registers a scheduled task masquerading as an Avast browser update, and uses the Dropbox API for command-and-control and data exfiltration; file hashes are provided for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
