Japan warns of attacks linked to North Korean Kimsuky hackers
ID: d4d17dd9-5f5e-5d86-968e-d5325ca8ca46
STIX ID: report--d4d17dd9-5f5e-5d86-968e-d5325ca8ca46
Feed Name: Bleeping Computer
Threat Score
JPCERT/CC warns that the North Korean APT group Kimsuky targeted Japanese organizations in 2024 using phishing emails with malicious ZIP and CHM attachments that execute VBS and PowerShell payloads to collect system information, log keystrokes/clipboard data, and exfiltrate credentials and files; ASEC and JPCERT/CC observed recent samples with stronger obfuscation and shared IoCs, urging vigilance against CHM files and similar delivery mechanisms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
