logo

Kimsuky Hacker Group Unleashes Updated Phishing Strategies and Malware Infections

ID: 40913649-d419-5abc-89f7-b39a1cf5be45

STIX ID: report--40913649-d419-5abc-89f7-b39a1cf5be45

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-05-12

Date Updated: 2026-04-19

Author: Mandvi

...
...

Kimsuky (aka Black Banshee) is running a sophisticated phishing campaign that drops an obfuscated VBScript which launches a PowerShell stealer; the modular malware gathers browser credentials, crypto-wallet data, system inventory and logs (including keylogging and clipboard capture), uses anti-VM checks to evade analysis, and exfiltrates data in chunks to C2, with several IOCs (filenames and hashes) provided; behavioral endpoint protections are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.