钓鱼之王 —— Kimsuky近期以多个话题针对韩国的鱼叉式钓鱼攻击活动分析

2022-07-25 • Qianxin • King of Phishing: Analysis of recent Kimsuky spear-phishing attacks against South Korea using multiple themes •

https://ti.qianxin.com/blog/articles/king-of-phishing-analysis-of-kimsuky's-recent-spear-phishing-attacks-targeting-south-korea-with-multiple-topics/

Thumbnail for 钓鱼之王 —— Kimsuky近期以多个话题针对韩国的鱼叉式钓鱼攻击活动分析

Qianxin attributes with medium confidence a set of spear-phishing attacks against South Korean targets to Kimsuky, noting the group's focus on defense, education, energy, government, healthcare, and think tanks. The campaign used HWP lure documents themed around North Korean defector advisory surveys, Korea Policy Broadcasting invitations, and North Korea COVID-19 analysis to induce user interaction and execute embedded OLE or EPS content. The execution chain dropped temporary files, ran PowerShell, injected MSF-generated shellcode into legitimate Windows processes such as help.exe or winhlp32.exe, and used fileless follow-on loading to reduce detection. One sample used mshta.exe and a scheduled task named EstSoft\Alcap\Report to periodically contact C2, parse returned commands, execute them via cmd.exe, and post results back. Reported indicators include MD5 hashes such as 905745E2A196D7F8D7C2F9547F5B9E67 and infrastructure including hanainternational.net and work3.b4a.app.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7975bbbfcb75dabb3271a8f1a79d67a… 2022-06-01 2022-09-03
HASH c6bdd19f7ee5a27e42eef26204fb9d0… 2022-07-25 2022-07-25
HASH 7847394c36eb24184f74c8610b1c420… 2022-06-20 2022-07-25
URL https://work3.b4a.app/download.… 2022-06-20 2022-07-25
HASH a73c3f27b0c6ccb8eddde4c0b9d0089… 2022-06-01 2022-07-25
URL http://hanainternational.net/ed… 2022-06-01 2022-07-25
DOMAIN hanainternational.net 2022-05-09 2022-07-25

Related Actors

Related Reports

« Back