GitLab 플랫폼을 이용한 Kimsuky 공격 사례

2026-04-03 ESTSecurity Kimsuky attack case using the GitLab platform

https://blog.alyac.co.kr/5743

Thumbnail for GitLab 플랫폼을 이용한 Kimsuky 공격 사례

Kimsuky is assessed to have distributed malicious `.pdf.lnk` files disguised as a resume and North Korea policy documents, using a multi-stage PowerShell chain to collect host information and exfiltrate it. The infection saves and runs `firefox.ps1`, establishes persistence with a Microsoft Edge-themed scheduled task, deploys `facebook.ps1` as a recurring downloader, and executes `news.ps1` as the final information-stealing payload. The campaign abuses GitLab rather than previously observed GitHub infrastructure, using GitLab-hosted encrypted payload files and the GitLab API to upload AES-256-encrypted victim data. ESRC lists two LNK MD5 hashes and two GitLab repository URLs as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2df24d850d6a50410e6503bc449a617… 2026-04-03 2026-08-09
HASH 863f1405a190e2d87f06c5a9383b91b… 2026-04-03 2026-08-09
URL https://gitlab.com/kevin-group5… 2026-04-03 2026-04-03
URL https://gitlab.com/arkiler-grou… 2026-04-03 2026-04-03

Related Actors

Related Reports

2026-04-17 • 62% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing, T1027 • Published within a month
« Back