logo

Dissecting the Infection Chain: Technical Analysis of the Kimsuky JavaScript Dropper

ID: 1b2132be-e890-5f94-9df0-9cdc95f9b6bd

STIX ID: report--1b2132be-e890-5f94-9df0-9cdc95f9b6bd

Feed Name: Pulsedive Blog

Threat Score
75/100

Date Published: 2025-11-05

Date Updated: 2026-04-28

Author: Pulsedive Threat Research

...
...

This report analyzes a Kimsuky JavaScript dropper (Themes.js) that fetches additional JavaScript stages from an adversary-controlled subdomain on medianewsonline.com, collects system and process information and directory listings, encodes and exfiltrates the data in .cab files via POST requests (using certutil as a LOLBIN), and persists by writing Themes.js to %APPDATA% and creating a scheduled task; the report includes sample hashes, network IOCs, decoded payload details, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.