North Korea’s Kimsuky Group Uses AI-Generated Military IDs in New Attack
ID: 3b126827-db9a-554e-b2b2-19e1b93759c0
STIX ID: report--3b126827-db9a-554e-b2b2-19e1b93759c0
Feed Name: HackRead
Threat Score
Kimsuky, a North Korean APT, is running a phishing campaign using AI-generated deepfake military ID images to trick recipients into opening a ZIP that executes hidden scripts; the attack chain downloads LhUdPC3G.bat from jiwooeng.co.kr and installs a persistent scheduled task (HncAutoUpdateTaskMachine) via batch and AutoIt scripts. Researchers highlight the use of identifiable code strings and recommend EDR to detect the obfuscated script-based activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
