logo

Trend Analysis on Kimsuky Group’s Attacks Using AppleSeed

ID: 0ed97e52-c679-50af-837e-71a4e6817e4d

STIX ID: report--0ed97e52-c679-50af-837e-71a4e6817e4d

Feed Name: ASEC

Threat Score
90/100

Date Published: 2023-12-28

Date Updated: 2026-04-26

Author: Sanseo

...
...

The report describes Kimsuky (North Korea–supported) spearphishing campaigns that deploy backdoors and infostealers—notably AppleSeed and a Golang variant AlphaSeed—via JavaScript droppers, LNK shortcuts, and droppers that use Regsvr32 with required execution arguments to evade sandboxes. It documents AlphaSeed’s ChromeDP-based C2 (cookie-based login), Meterpreter and VNC/HVNC remote access tools, shifts from RDP to Chrome Remote Desktop, persistence locations and filename decoys under %APPDATA%/%PROGRAMDATA%, detection names, sample MD5s, and C2 URLs, concluding with mitigation advice and file/behavior detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.