It's 2024 and North Korea's Kimsuky gang is exploiting Windows Help files
ID: e8f59851-c85d-50d5-9aa0-962276eeec51
STIX ID: report--e8f59851-c85d-50d5-9aa0-962276eeec51
Feed Name: The Register (Security)
Threat Score
Rapid7 reports that North Korean APT Kimsuky (aka Black Banshee/Thallium/APT43) is running a campaign using poisoned CHM files (and ISO/VHD/ZIP/RAR containers) to deliver VBScript-based infostealers that collect machine and document data and establish registry persistence; Rapid7 published indicators of compromise and attributes the activity to Kimsuky with moderate confidence, identifying South Korea as the primary target and signs of activity in Germany.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
