기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장
2026-09-09 • ESTSecurity • New Kimsuky LNK Malware Uses Function-Specific C2 Servers •
ESTsecurity linked a malicious LNK campaign targeting Korean organizations to Kimsuky based on its delivery method, document lures, and established targeting patterns. The infection chain uses batch scripts, renamed Windows utilities, NirCmd, and a five-minute scheduled task while GitHub distributes common and MachineGuid-specific commands. Infection notifications are sent through a Wasmer-hosted WordPress endpoint, collected system information is uploaded through the Dropbox API, and selected hosts can be moved to quieter repositories for subsequent remote access. Separating these functions across trusted services makes the campaign harder to reconstruct and disrupt through any single network control.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | free.pinggy.io | 2026-09-09 | 2026-09-09 |
| URL | https://nafwo.wasmer.app/wp-con… | 2026-09-09 | 2026-09-09 |
| URL | https://raw.githubusercontent.c… | 2026-09-09 | 2026-09-09 |
| URL | https://raw.githubusercontent.c… | 2026-09-09 | 2026-09-09 |
| URL | https://raw.githubusercontent.c… | 2026-09-09 | 2026-09-09 |
| HASH | a405090029b6b95a65a8884593dfe30d | 2026-09-09 | 2026-09-09 |
| HASH | a253fa2200e4ba4d64592d87db81b8f6 | 2026-09-09 | 2026-09-09 |
| HASH | c7d258f44b4a09850d7cb9a0142ea88e | 2026-09-09 | 2026-09-09 |
| HASH | 5fe869d0d68086a231574f83a6c8c35e | 2026-09-09 | 2026-09-09 |