Kimusky Hackers Leverage ClickFix Method to Deploy Malicious Scripts on Target Systems
ID: d0337d17-040a-5be8-ba4b-edc6340da3ae
STIX ID: report--d0337d17-040a-5be8-ba4b-edc6340da3ae
Feed Name: Cyber Press
Genians Security Center reports a sophisticated Kimsuky campaign using the "ClickFix" social-engineering technique to coerce victims into running obfuscated PowerShell or script commands that deploy multi-stage payloads (including RATs such as QuasarRAT), establish persistence, and exfiltrate data; the report provides extensive IoCs (MD5s, domains, IPs), infrastructure and linguistic attribution to North Korea, and recommends EDR behavioral detection and security awareness to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
