2026년 Kimsuky의 스피어피싱·지속성 전략

2026-09-08 • ENKI • Kimsuky's Spearphishing and Persistence Strategies in 2026 •

https://www.dailysecu.com/form/html/pascon/pdf/2026/KCSCON2026_B-1.pdf

Attachments

source_3989.pdf (5 MB)

Thumbnail for 2026년 Kimsuky의 스피어피싱·지속성 전략

Kimsuky continues to target South Korean military, government, and public-sector organizations with tailored spearphishing designed for long-term espionage access. Its delivery methods include malicious LNK files disguised as documents, counterfeit software-download pages, and fake meeting sites that execute a malicious camera-patch script before redirecting victims to a legitimate page. Persistence and remote access rely on scheduled tasks, Run keys, hidden administrator accounts, patched RDP components, Chrome Remote Desktop, AnyDesk, proxy tools, and a Gmail-stealing Chrome extension. The group also abuses GitHub, GitLab, and Codeberg repositories to host malicious scripts, stolen information, remote-access tools, and lure documents.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ibizplus.n-e.kr 2026-05-27 2026-09-18
URL https://codeberg.org/tomas-89/r… 2026-09-08 2026-09-08
URL https://gitlab.com/galata20/shi… 2026-09-08 2026-09-08
URL https://gitlab.com/kickball12/b… 2026-09-08 2026-09-08
URL https://github.com/nemotomui/ga… 2026-09-08 2026-09-08
URL https://github.com/Balladeba/sh… 2026-09-08 2026-09-08
URL https://github.com/bormanye/chs… 2026-09-08 2026-09-08
URL https://github.com/kissmontra1/… 2026-09-08 2026-09-08
URL https://github.com/mongdolma/ka… 2026-09-08 2026-09-08
URL https://github.com/jecoma/basco 2026-09-08 2026-09-08
URL https://github.com/cryseuk/ayuk… 2026-09-08 2026-09-08
URL https://github.com/tomas23492/c… 2026-09-08 2026-09-08
URL https://github.com/shantez441/E… 2026-09-08 2026-09-08
URL https://codeberg.org/tomas-89/ 2026-08-24 2026-09-08

Related Actors

Related Reports

« Back