MB-0010

2026-06-29 • Synaptic SecurityInside Kimsuky’s CHM Tradecraft: Multi-Stage Exec…

MB-0010 is a tracking label associated with APT43 and Kimsuky activity. A documented intrusion used a Korean-language CHM decoy to launch hidden PowerShell, retrieve staged VBScript, profile the host, establish scheduled-task persistence, exfiltrate system inventory, and conditionally retrieve a final payload.

Related Actors

Related Reports in This Cluster

Top Authors

View MB-0010 reports only

View MB-0010 reports only