Malware Disguised as Installer from Korean Public Institution (Kimsuky Group)
ID: 932e4ac5-a9f4-5e5f-ad85-2a64a853eb4f
STIX ID: report--932e4ac5-a9f4-5e5f-ad85-2a64a853eb4f
Feed Name: ASEC
AhnLab ASEC details Kimsuky distributing a signed dropper masquerading as a Korean public-institution installer that unpacks a passworded archive to deploy the Endoor backdoor (Golang); Endoor provides remote command execution, file transfer, SOCKS5 proxy and was observed with Nikidoor, Mimikatz usage, and a screenshot-capture/exfiltration component. The report includes attack logs, MD5s, C2 domains/URLs (including ngrok-free.app and specific download URLs), file detections, and a recommendation to update V3 to block infection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
