logo

North Korean Hackers Target Pharma Firms with Malware-Laced Excel Attacks

ID: 12d1b63e-c7a3-5a4b-a28c-d6a68b29cc6d

STIX ID: report--12d1b63e-c7a3-5a4b-a28c-d6a68b29cc6d

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Mayura Kathir

...
...

North Korean APT Kimsuky is conducting a targeted campaign against pharmaceutical and life‑science organizations by sending ZIP attachments containing LNK files that masquerade as Excel spreadsheets. When opened the LNK launches cmd.exe and an obfuscated PowerShell chain that decodes payloads, displays a decoy workbook, uploads system info to Dropbox, retrieves further payloads (e.g., JavaScript, scheduled tasks), and establishes persistence to exfiltrate research and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.