LOTSを活用して進化を続けるKimJongRAT
ID: 9f770377-844c-5054-b566-4751ac3a2d6a
STIX ID: report--9f770377-844c-5054-b566-4751ac3a2d6a
Feed Name: IIJ Security Diary
Threat Score
This report documents a May 2026 multi-stage attack attributed to the Kimsuky APT that distributed KimJongRAT via malicious LNK/HTA files hosted on GitHub Releases and Google Drive; it explains execution flows for DLL and PowerShell variants, newly observed features (dynamic C2 retrieval and MeshAgent deployment), takedown activity on GitHub, and includes file and network IoCs to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
