Kimsuky Hacker Group Unleashes Updated Phishing Strategies and Malware Infections
ID: 40913649-d419-5abc-89f7-b39a1cf5be45
STIX ID: report--40913649-d419-5abc-89f7-b39a1cf5be45
Feed Name: Cyber Press
Threat Score
Kimsuky (aka Black Banshee) is running a sophisticated phishing campaign that drops an obfuscated VBScript which launches a PowerShell stealer; the modular malware gathers browser credentials, crypto-wallet data, system inventory and logs (including keylogging and clipboard capture), uses anti-VM checks to evade analysis, and exfiltrates data in chunks to C2, with several IOCs (filenames and hashes) provided; behavioral endpoint protections are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
