수입 신고서를 위장하여 국내 연구 기관을 노리는 Kimsuky

2023-11-21 • Ahnlab • Kimsuky targets domestic research institutes by disguising import declarations. •

https://asec.ahnlab.com/ko/59209/

Thumbnail for 수입 신고서를 위장하여 국내 연구 기관을 노리는 Kimsuky

ASEC reported Kimsuky distributing a malicious JSE dropper disguised as an import declaration to South Korean research institutes. The dropper contains obfuscated PowerShell, a Base64-encoded backdoor, and a benign PDF with target information, then writes a backdoor under ProgramData and executes it with rundll32.exe. The malware copies itself as IconCache.db for scheduled-task persistence, collects antivirus, network, host, user, and OS data, encodes command output for C2, and supports command execution and uploads to rscnode.dothome.co.kr.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 97df5304f53fec6a5d2d2bd75b9310a… 2023-11-21 2024-03-05
HASH b1361b67025b44a86af61c1863c98fb… 2023-11-21 2023-11-30
URL http://rscnode.dothome.co.kr/in… 2023-11-21 2023-11-30
URL http://rscnode.dothome.co.kr/up… 2023-11-21 2023-11-30
DOMAIN rscnode.dothome.co.kr 2023-11-21 2023-11-30

Related Actors

Related Reports

« Back