Kimsuky组织利用Dropbox云端实施行动分析

2024-01-30 • Sangfor • Kimsuky organization leverages Dropbox cloud for operational analytics •

https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247522061&idx=1&sn=22e56ee213d9e5229371ad3e082ebfab&chksm=ce461c1df931950b245134a250b6bf4bea489d75b556cb450548569c0c6d50d3bacc00a8efe0&scene=178&cur_album_id=2867627575890837505#rd

Thumbnail for Kimsuky组织利用Dropbox云端实施行动分析

Sangfor links this Kimsuky activity to malicious LNK files disguised as Korean PDF or HWP documents for targets in cryptocurrency, government, diplomacy, media, and North Korea policy circles. One lure posed as a Korean cryptocurrency trading lecture and used PowerShell to pull ps.bin from Dropbox, which then loaded r_enc.bin and a TutClient remote-control component. The chain wrote a VBS stage under the Windows Templates directory, fetched a decoy PDF from hyojadong.kr, created scheduled tasks, and downloaded later PowerShell payloads. The operation used Dropbox for both staging and exfiltration, including scripts that collected host and file information and uploaded the results through Dropbox APIs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 617a4a83e7fb10a4a9ef993cdfe4d83… 2024-01-30 2024-06-12
HASH a53caf4805a1b9c0b7fca4e2e3e21fb… 2024-01-30 2024-04-17
HASH befa4094eb7ceb31be76ec98b11353b… 2024-01-30 2024-04-17
HASH a30f649b85bbec3809dbb6f485c5181… 2024-01-30 2024-04-17
DOMAIN gbionet.com 2024-01-30 2024-04-17
IPv4 122.155.191.33 2024-01-30 2024-04-17
HASH 0a5151c9878b592a202c07e7c02ed46… 2023-12-29 2024-04-17
URL https://hyojadong.kr/js/slick/d… 2024-01-30 2024-03-28
DOMAIN hyojadong.kr 2024-01-30 2024-03-28
URL http://gbionet.com/ 2024-01-30 2024-01-30
HASH e1f7cb002b25f60f71d551df45eef5f… 2023-09-26 2024-01-30

Related Actors

Related Reports

« Back