Kim Sooki again? This time, it was disguised as a request for seafood ingredients
2026-09-02 • Ahnlab •
Kimsuky-linked operators distributed a malicious LNK disguised as a seafood ingredient purchase-review request to South Korean users. Execution displayed a legitimate HWP decoy while extracting PowerShell and JavaScript components, establishing a scheduled task that ran approximately every 14 minutes, and collecting host, user, network, and process information. The malware used Backblaze B2 for command-and-control, uploaded stolen system data, downloaded additional commands, executed them through hidden CMD files, and deleted selected artifacts. AhnLab attributed the activity to Kimsuky based on code and workflow similarities with earlier LNK campaigns associated with the group.