APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析

2026-05-13 Qihoo360 Analysis of an APT-C-55 (Kimsuky) Attack Campaign Distributing Malicious Payloads via GitHub and Dropbox

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508584&idx=1&sn=3983faed8f799809ecc23eb552e73548&scene=178

Thumbnail for APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析

Kimsuky, also tracked as APT-C-55 and BabyShark, is described as an espionage-focused actor that targets government, diplomatic, think tank, media, and academic organizations tied to the Korean Peninsula and other regions. The observed campaign begins with a phishing LNK file named as a Korean-language China CMG interview document, which decrypts and opens a decoy while using a copied curl binary to download taskschd.vbs from Dropbox. The VBS stage pulls a batch script from GitHub, which then downloads two PowerShell scripts from Dropbox and GitHub. One PowerShell script creates a GoogleUpdateTaskMachineUA-named scheduled task for persistence and uploads host information to GitHub, while the other decrypts content from fox.png with a modified RC4 routine and reflectively loads a .NET payload identified as an AsyncRAT variant for sensitive information theft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 112.216.9.171 2026-05-13 2026-05-13
URL https://raw.githubusercontent.c… 2026-05-13 2026-05-13
URL https://raw.githubusercontent.c… 2026-05-13 2026-05-13
URL https://www.dropbox.com/scl/fi/… 2026-05-13 2026-05-13
URL https://raw.githubusercontent.c… 2026-05-13 2026-05-13
URL https://www.dropbox.com/scl/fi/… 2026-05-13 2026-05-13
HASH 7aa4fba7f1270af6afc326c172ccac3… 2026-05-13 2026-05-13
HASH 981dadc1a7ab50d6ff600a69c904a35… 2026-05-13 2026-05-13
HASH 456ed6926b706c203ac65b5174ac2ce… 2026-05-13 2026-05-13
HASH 68334f95f4ec1c725bbf3bb625a99a0… 2026-05-13 2026-05-13
HASH 4caf1bb6a757eefad74359048052072… 2026-05-13 2026-05-13
HASH 70a7f0aeda59f8563031b5ab4554b52… 2026-05-13 2026-05-13
HASH 531aacc5cfe1abb14aaf55a2128940d… 2026-05-13 2026-05-13
HASH 7ed250363d5c2714a79e826cef1690e… 2026-05-13 2026-05-13
HASH 18fa10ff013cf82974f00875e23dae4… 2026-05-13 2026-05-13
HASH 7832dcef8aded30ec042410c10f78f7… 2026-05-13 2026-05-13
HASH e49399502d455dbd38f1140bffa7617… 2026-05-13 2026-05-13

Related Actors

Related Reports

« Back