기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장

2026-09-09 • ESTSecurity • New Kimsuky LNK Malware Uses Function-Specific C2 Servers •

https://blog.alyac.co.kr/5777

Thumbnail for 기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장

ESTsecurity attributes a new malicious LNK operation targeting South Korean organizations to Kimsuky based on the group's established shortcut-based delivery and Korean business-document lures. The chain uses batch scripts, renamed Windows utilities, and scheduled tasks to perform reconnaissance and maintain five-minute execution intervals. GitHub distributes common and MachineGuid-specific commands, a Wasmer-hosted WordPress endpoint records infection beacons, and Dropbox receives stolen data. Selected hosts can be redirected to separate repositories that reduce reconnaissance activity or deploy reverse-tunnel access through Pinggy.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN free.pinggy.io 2026-09-09 2026-09-09
URL https://nafwo.wasmer.app/wp-con… 2026-09-09 2026-09-09
URL https://raw.githubusercontent.c… 2026-09-09 2026-09-09
URL https://raw.githubusercontent.c… 2026-09-09 2026-09-09
URL https://raw.githubusercontent.c… 2026-09-09 2026-09-09
HASH a405090029b6b95a65a8884593dfe30d 2026-09-09 2026-09-09
HASH a253fa2200e4ba4d64592d87db81b8f6 2026-09-09 2026-09-09
HASH 9f99074c387083a552dcdf5ce0982ae… 2026-09-09 2026-09-09
HASH 0fc425836eb854914525302b59cb830… 2026-09-09 2026-09-09

Related Actors

Related Reports

« Back