2026년 Kimsuky의 스피어피싱·지속성 전략
2026-09-08 • ENKI • Kimsuky's Spearphishing and Persistence Strategies in 2026 •
https://www.dailysecu.com/form/html/pascon/pdf/2026/KCSCON2026_B-1.pdf
Attachments
source_3989.pdf (5 MB)
Kimsuky continues to target South Korean military, government, and public-sector organizations with tailored spearphishing designed for long-term espionage access. Its delivery methods include malicious LNK files disguised as documents, counterfeit software-download pages, and fake meeting sites that execute a malicious camera-patch script before redirecting victims to a legitimate page. Persistence and remote access rely on scheduled tasks, Run keys, hidden administrator accounts, patched RDP components, Chrome Remote Desktop, AnyDesk, proxy tools, and a Gmail-stealing Chrome extension. The group also abuses GitHub, GitLab, and Codeberg repositories to host malicious scripts, stolen information, remote-access tools, and lure documents.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ibizplus.n-e.kr | 2026-05-27 | 2026-09-08 |