군사·안보 학술지로 위장한 Kimsuky 정찰용 악성코드

2026-06-29 Hauri Kimsuky Reconnaissance Malware Disguised as a Military and Security Journal

https://hauri.co.kr/security/security_view.html?intSeq=89

Attachments

2026-06-29ììëìë³ê³_ìêµìÂìë³íì_ìëììíKimsukyì_ììì_ìì½ë.pdf (801 KB)

Thumbnail for 군사·안보 학술지로 위장한 Kimsuky 정찰용 악성코드

Kimsuky-linked malware masqueraded as a Korea Institute for Military Affairs monthly military and security publication, using a document-like LNK file to start a staged infection chain. Hauri observed Dropbox and GitHub being abused to host and deliver VBE, batch, and PowerShell components, with the final payload collecting system information, Downloads folder listings, and running process data before uploading results to attacker GitHub infrastructure. The report ties the public Music storage path and the GoogleUpdateTaskMachineUA-style scheduled task name to patterns previously seen in Kimsuky activity, indicating reconnaissance and persistence rather than immediate destructive impact.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 686b131d3ae578ba0706c2a1786bf1ea 2026-06-29 2026-06-29
HASH e9ab83dfc335b98d02137becb89fe828 2026-06-29 2026-06-29
HASH b0433d425a10739f59585ba48ab8c92b 2026-06-29 2026-06-29
URL https://github.com/tomas23492/c… 2026-06-29 2026-06-29
URL https://raw.githubusercontent.c… 2026-06-29 2026-06-29
URL https://github.com/tomas23492/c… 2026-06-29 2026-06-29
URL https://www.dropbox.com/scl/fi/… 2026-06-29 2026-06-29
URL https://www.dropbox.com/scl/fi/… 2026-06-29 2026-06-29

Related Actors

Related Reports

« Back