또 김수키? 이번엔 수산 식자재 구매 요청서로 위장

2026-09-02 Ahnlab Kimsuky Again? This Time Disguised as a Seafood Ingredient Purchase Request

https://asec.ahnlab.com/ko/95216

Thumbnail for 또 김수키? 이번엔 수산 식자재 구매 요청서로 위장

Kimsuky-linked operators distributed a malicious LNK disguised as a seafood ingredient purchase-review request to South Korean users. Execution displayed a legitimate HWP decoy while extracting PowerShell and JavaScript components, establishing a scheduled task that ran approximately every 14 minutes, and collecting host, user, network, and process information. The malware used Backblaze B2 for command-and-control, uploaded stolen system data, downloaded additional commands, executed them through hidden CMD files, and deleted selected artifacts. AhnLab attributed the activity to Kimsuky based on code and workflow similarities with earlier LNK campaigns associated with the group.

Related Actors

Related Reports

« Back