군사·안보 학술지로 위장한 Kimsuky 정찰용 악성코드
2026-06-29 • Hauri • Kimsuky Reconnaissance Malware Disguised as a Military and Security Journal •
Attachments
Kimsuky-linked malware masqueraded as a Korea Institute for Military Affairs monthly military and security publication, using a document-like LNK file to start a staged infection chain. Hauri observed Dropbox and GitHub being abused to host and deliver VBE, batch, and PowerShell components, with the final payload collecting system information, Downloads folder listings, and running process data before uploading results to attacker GitHub infrastructure. The report ties the public Music storage path and the GoogleUpdateTaskMachineUA-style scheduled task name to patterns previously seen in Kimsuky activity, indicating reconnaissance and persistence rather than immediate destructive impact.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 686b131d3ae578ba0706c2a1786bf1ea | 2026-06-29 | 2026-06-29 |
| HASH | e9ab83dfc335b98d02137becb89fe828 | 2026-06-29 | 2026-06-29 |
| HASH | b0433d425a10739f59585ba48ab8c92b | 2026-06-29 | 2026-06-29 |
| URL | https://github.com/tomas23492/c… | 2026-06-29 | 2026-06-29 |
| URL | https://raw.githubusercontent.c… | 2026-06-29 | 2026-06-29 |
| URL | https://github.com/tomas23492/c… | 2026-06-29 | 2026-06-29 |
| URL | https://www.dropbox.com/scl/fi/… | 2026-06-29 | 2026-06-29 |
| URL | https://www.dropbox.com/scl/fi/… | 2026-06-29 | 2026-06-29 |