Inside Kimsuky’s Latest Cyberattack: Analyzing Malicious Scripts and Payloads

2025-03-25 K7Security Labs

https://labs.k7computing.com/index.php/inside-kimsukys-latest-cyberattack-analyzing-malicious-scripts-and-payloads/

K7 Labs analyzes a Kimsuky attack chain built from a ZIP archive containing a VBScript, a PowerShell script, and two encoded text files. The VBScript dynamically builds and runs a command that launches 1.ps1, which decodes 1.log, collects the BIOS serial number, creates a machine-specific temp directory, and aborts if it detects a virtual machine. The decoded PowerShell functions support system profiling, browser and extension data theft from Edge, Firefox, Chrome, and Naver Whale, crypto-wallet extension file collection, persistence, C2-driven download and file operations, and chunked HTTP upload of exfiltrated data. A later decoded 2.log component adds keylogging, clipboard monitoring, and window-title logging, giving the operator reconnaissance and credential-theft capabilities before further C2 commands are issued.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 97d1bd607b4dc00c356dd873cd4ac30… 2025-03-25 2025-06-17
HASH f73164bd4d2a475f79fb7d0806cfc3d… 2025-03-25 2025-06-17
HASH b1f9b450b97320de54f2450ace151b4… 2025-03-25 2025-04-04

Related Actors

Related Reports

« Back