기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장

2026-09-09 ESTSecurity New Kimsuky LNK Malware Uses Function-Specific C2 Servers

https://blog.alyac.co.kr/5777

Thumbnail for 기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장

ESTsecurity linked a malicious LNK campaign targeting Korean organizations to Kimsuky based on its delivery method, document lures, and established targeting patterns. The infection chain uses batch scripts, renamed Windows utilities, NirCmd, and a five-minute scheduled task while GitHub distributes common and MachineGuid-specific commands. Infection notifications are sent through a Wasmer-hosted WordPress endpoint, collected system information is uploaded through the Dropbox API, and selected hosts can be moved to quieter repositories for subsequent remote access. Separating these functions across trusted services makes the campaign harder to reconstruct and disrupt through any single network control.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN free.pinggy.io 2026-09-09 2026-09-09
URL https://nafwo.wasmer.app/wp-con… 2026-09-09 2026-09-09
URL https://raw.githubusercontent.c… 2026-09-09 2026-09-09
URL https://raw.githubusercontent.c… 2026-09-09 2026-09-09
URL https://raw.githubusercontent.c… 2026-09-09 2026-09-09
HASH a405090029b6b95a65a8884593dfe30d 2026-09-09 2026-09-09
HASH a253fa2200e4ba4d64592d87db81b8f6 2026-09-09 2026-09-09
HASH c7d258f44b4a09850d7cb9a0142ea88e 2026-09-09 2026-09-09
HASH 5fe869d0d68086a231574f83a6c8c35e 2026-09-09 2026-09-09

Related Actors

Related Reports

« Back