Emulating Kimsuky's Initial Access

2026-06-22 0x00sec

https://0x00sec.org/emulating-kimsukys-initial-access/

Thumbnail for Emulating Kimsuky's Initial Access

Kimsuky's DEEP#DRIVE initial-access chain used phishing-delivered LNK files disguised as documents to launch hidden PowerShell, retrieve hosted scripts and payloads, and open a decoy PDF. The emulation reproduces scheduled-task persistence and payload execution from user-writable directories while applying LNK target-spoofing techniques. Sysmon telemetry highlights `explorer.exe` spawning PowerShell and the unusual PowerShell-to-PDF-reader process lineage, for which the author provides a Defender KQL detection example. The downloaded files and Dropbox links in the post belong to the author's proof of concept rather than confirmed campaign indicators.

Related Actors

Related Reports

« Back