KTA082

2024-03-05 • KrollTODDLERSHARK: ScreenConnect Vulnerability Exploit…

KTA082 is Kroll’s tracking designation for the North Korean APT group more widely known as Kimsuky. In March 2024, Kroll linked the designation to an attempted intrusion that exploited authentication-bypass vulnerabilities in ConnectWise ScreenConnect to deploy a newly observed BABYSHARK variant. After gaining interactive access, the operator used command-line and Microsoft utilities to execute heavily obfuscated Visual Basic stages whose randomized code, junk content, and unique download paths complicated detection. The malware disabled Office macro warnings, collected host, user, network, security-product, process, and software information, encoded the results with a native certificate utility, and exfiltrated them to command-and-control infrastructure. It also established a scheduled task that repeatedly retrieved and executed additional code. Kroll connected this behavior to Kimsuky’s earlier macro-based spear-phishing and information-stealing operations while retaining uncertainty about the final payload delivered during the observed incident.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster