DropBox를 이용한 Kimsuky 악성코드

2024-03-22 • Hauri • ( Document No : DT-20240322-001 ) •

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=60

Attachments

2024-03-22ììëìë³ê³ìDropBoxë¼ììíKimsukyììì½ë.pdf (1 MB)

Hauri reports that Kimsuky has been distributing malicious Windows shortcut files since December 2023 against security-related targets and cryptocurrency investors, with a focus on information theft. The LNK execution chain runs PowerShell, uses Dropbox refresh and access tokens to retrieve encrypted payloads such as /step1/ps.bin, decrypts and executes staged scripts, and establishes persistence through scheduled tasks that run every 10 minutes. The malware collects process and service lists, system information, firewall settings, installed antivirus products, and file listings from user folders before AES-encrypting the results and uploading them to attacker-controlled Dropbox paths. Later stages include keylogging, browser credential theft, Google Drive-hosted payload retrieval, and UltraVNC deployment with a firewall rule allowing port 5900 for remote control. The report provides multiple MD5 hashes for LNK lures and related files, making it useful for tracking Kimsuky cloud-storage-based delivery and post-compromise collection tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f262588c48d2902992ffd275d2be636… 2024-03-18 2024-12-27
HASH 1b75f70c226c9ada8e79c3fdd987277… 2024-03-18 2024-12-27
HASH d912f49d24792aa7197509f76e2097a… 2024-03-22 2024-04-17
HASH befa4094eb7ceb31be76ec98b11353b… 2024-01-30 2024-04-17
HASH a30f649b85bbec3809dbb6f485c5181… 2024-01-30 2024-04-17
URL https://hyojadong.kr/js/slick/d… 2024-01-30 2024-03-28
DOMAIN hyojadong.kr 2024-01-30 2024-03-28
HASH c47675700b20537374c86e7a5426f848 2024-03-22 2024-03-22
HASH d1f1019fb0f0810a8633bd0ef5a0d7b… 2024-03-22 2024-03-22

Related Actors

Related Reports

« Back