북한 해킹 조직 김수키(Kimsuky)에서 만든 악성코드-SW보안점검표(개발자 사전점검용)_v2.0_beta.xlsm(2023.02.02)

2023-02-09 • Sakai • Malware created by Kimsuky disguised as a software security checklist XLSM document •

https://wezard4u.tistory.com/6357

Thumbnail for 북한 해킹 조직 김수키(Kimsuky)에서 만든 악성코드-SW보안점검표(개발자 사전점검용)_v2.0_beta.xlsm(2023.02.02)

The Korean analysis attributes a malicious VBS payload disguised as a software security checklist XLSM document to Kimsuky activity targeting South Korean think tanks, industry, nuclear and defense-related organizations, and North Korea-focused personnel. The script drops files under ProgramData or the Windows directory, decodes a Base64 blob with an XOR key, registers the resulting payload with regsvr32, and uses persistence-related registry entries. Reported infrastructure includes qwert.mine[.]bz and 216.189.154[.]6:80, with detections referencing AppleSeed/Kimsuky-family VBS downloaders. The article frames the lure as part of continuing DPRK-linked social engineering against people interested in inter-Korean and security issues.

Indicators of Compromise

Type Value First Seen Last Seen
HASH db18e23bebb8581ba5670201cea98cc… 2022-09-14 2024-03-12
URL http://qwert.mine.bz/index.php 2022-09-14 2024-03-12
DOMAIN qwert.mine.bz 2022-09-14 2024-03-12
IPv4 216.189.154.6 2022-08-25 2024-03-12

Related Actors

Related Reports

« Back