Inside Kimsuky’s Abuse of Legitimate Remote Control Tools Across Northeast Asia

2026-08-20 ENKI

https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia

Thumbnail for Inside Kimsuky’s Abuse of Legitimate Remote Control Tools Across Northeast Asia

Kimsuky targeted organizations in South Korea and Japan during the first half of 2026 with OneDrive-delivered spearphishing links leading to malicious LNK files. The infection chain established scheduled PowerShell execution, collected system information and Thunderbird, Outlook, and Gmail data, and recorded keystrokes. The actor installed Chrome Remote Desktop and AnyDesk to maintain redundant remote-control access while concealing related windows and icons. ENKI Whitehat linked the campaign to Kimsuky through matching email-theft methods, AnyDesk deployment scripts, regional victimology, and overlap with previously observed tooling and TTPs.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://160.187.147.119/any/bima… 2026-08-20 2026-08-20
URL http://160.187.147.119/any/vpos… 2026-08-20 2026-08-20
URL http://160.187.147.119/any/sch.… 2026-08-20 2026-08-20
URL http://160.187.147.119/any/atta… 2026-08-20 2026-08-20
URL http://160.187.147.119/any/mnfs… 2026-08-20 2026-08-20
URL http://160.187.147.119/any/app.… 2026-08-20 2026-08-20
URL https://sweet-iki-4263.holy.jp/… 2026-08-20 2026-08-20
URL http://103.249.117.183/receive.… 2026-08-20 2026-08-20
URL http://103.249.117.183/1.bat 2026-08-20 2026-08-20
URL http://103.77.242.187/receive.p… 2026-08-20 2026-08-20
URL http://103.77.242.187/logo.png 2026-08-20 2026-08-20
URL http://103.77.242.187/JINF.pdf 2026-08-20 2026-08-20
URL https://1drv.ms/u/c/2c732f32393… 2026-08-20 2026-08-20
DOMAIN sweet-iki-4263.holy.jp 2026-08-20 2026-08-20
HASH 8e4410c65ca11664561e1b6036209122 2026-08-20 2026-08-20
HASH f3620e42e9c726c65ea7e14e3bf35464 2026-08-20 2026-08-20
HASH c774b3980151881d9d546710126b5ded 2026-08-20 2026-08-20
HASH eb80f7bddb699784baa9fbf2941eaf4a 2026-08-20 2026-08-20
HASH c08ea73bac08ea4f4665e9e0b0fdd2a8 2026-08-20 2026-08-20
HASH 51e1876c971c76d9664ad198af8a5b61 2026-08-20 2026-08-20
HASH 54089d9cf9c7d5ff9abbae88437f66a8 2026-08-20 2026-08-20
HASH f6f7a94c11ea0ee01cbbe674cfac7851 2026-08-20 2026-08-20
HASH 3ad9fbfad7ffb569b1aa24d4588edc60 2026-08-20 2026-08-20
HASH 0210f46648d4e36a98c2c0fae404f36d 2026-08-20 2026-08-20
HASH 633e672cce390d75f44f2e2357dec7b3 2026-08-20 2026-08-20
HASH 5727c0ff18c58b80bca5ce80575996bd 2026-08-20 2026-08-20
HASH e8aaa4f579e6be788929d3548b31bf6d 2026-08-20 2026-08-20
HASH d7dbce5d25aa483d9c5ec1223ed6bf6e 2026-08-20 2026-08-20
HASH 77a7dfdc7bd74cc47ac3f4f8e019936c 2026-08-20 2026-08-20
HASH 7c6ac06ccfa7648a4a8cc916c14d9f67 2026-08-20 2026-08-20
HASH 4c5474238c4b2ec2ca0698902c084624 2026-08-20 2026-08-20
HASH 5b49177d14f073bd7abf4c94688ebd84 2026-08-20 2026-08-20
HASH 94ed14ef07ac7504a3983ace8d894aae 2026-08-20 2026-08-20
HASH a2191f29f58b9f0cb576b7459ed6680d 2026-08-20 2026-08-20
HASH 300f7b8ff182c8c69a0c499cdda6f8b8 2026-08-20 2026-08-20
HASH e7da02737751f2f171aed28694b9554e 2026-08-20 2026-08-20
HASH 18e33961d2007c89311f7754313292b3 2026-08-20 2026-08-20
HASH cac69a696fc155717dabe641f22db0c9 2026-08-20 2026-08-20
HASH 95d049f184c02aa756b361c2dacb354d 2026-08-20 2026-08-20
HASH 8de25f181d32417fc34b2a77d2f4804b 2026-08-20 2026-08-20
IPv4 103.249.117.183 2026-08-20 2026-08-20
IPv4 210.183.177.217 2026-08-20 2026-08-20
IPv4 84.247.145.65 2026-08-20 2026-08-20
IPv4 160.187.147.119 2026-08-20 2026-08-20
IPv4 103.77.242.187 2026-08-20 2026-08-20

Related Actors

Related Reports

2026-04-17 • 50% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing, T1041
« Back