logo

Malware Disguised as Installer from Korean Public Institution (Kimsuky Group)

ID: 932e4ac5-a9f4-5e5f-ad85-2a64a853eb4f

STIX ID: report--932e4ac5-a9f4-5e5f-ad85-2a64a853eb4f

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-03-26

Date Updated: 2026-04-26

Author: Sanseo

...
...

AhnLab ASEC details Kimsuky distributing a signed dropper masquerading as a Korean public-institution installer that unpacks a passworded archive to deploy the Endoor backdoor (Golang); Endoor provides remote command execution, file transfer, SOCKS5 proxy and was observed with Nikidoor, Mimikatz usage, and a screenshot-capture/exfiltration component. The report includes attack logs, MD5s, C2 domains/URLs (including ngrok-free.app and specific download URLs), file detections, and a recommendation to update V3 to block infection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.