Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery

2026-06-29 Synaptic Security

https://blog.synapticsystems.de/inside-kimsukys-chm-tradecraft-multi-stage-execution-and-selective-payload-delivery/

Thumbnail for Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery

Kimsuky used a Korean-language CHM lure about North Korean food-crisis and right-to-food material to launch hidden PowerShell, decode a VBScript bootstrap, and retrieve staged payloads from DynV6-hosted infrastructure. The retrieved VBScript profiled the host with WMI, enumerated selected folders and running processes, uploaded a Base64 inventory as Info.txt, and installed a hidden hourly scheduled task named Edge Updater. A later loader requested a second VBScript stage that handed execution to PowerShell and contacted a final checkservice.php endpoint expected to define LogAction, but controlled replay returned an empty body, indicating selective final payload delivery. The report provides C2 domains, IPs, hashes, host artifacts, and behavioral detections for CHM-to-VBScript-to-PowerShell activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 152.32.138.15 2026-06-29 2026-06-29
IPv4 176.111.220.168 2026-06-29 2026-06-29
DOMAIN aointerviews.com 2026-06-29 2026-06-29
HASH 962e7a2a0b6ea9926f2198db06aa1d6… 2026-06-29 2026-06-29
HASH 21781885f9d6ebc5f9e0f828aacbe3d… 2026-06-29 2026-06-29
URL http://acnms.dmdoc.dynv6.net/sm… 2026-06-29 2026-06-29
URL http://acnms.dmdoc.dynv6.net/sm… 2026-06-29 2026-06-29
URL http://acnms.dmdoc.dynv6.net/sm… 2026-06-29 2026-06-29
IPv4 118.194.249.91 2026-06-29 2026-06-29
DOMAIN acnms.dmdoc.dynv6.net 2026-06-29 2026-06-29
HASH 0efbd18c77479b458078521c18bdad8… 2026-06-29 2026-06-29
IPv4 51.79.185.184 2026-04-11 2026-06-29
HASH 26ba5b01f614a215b948a5700338575… 2025-06-17 2026-06-29

Related Actors

Related Reports

2026-04-17 • 59% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, T1082, T1140 • Shares 1 IOC
2024-09-12 • 52% Match
#Kimsuky #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003
Shares tags: Kimsuky, T1082, T1140
« Back