Kimsuky 4

2024-04-10 • somedieyoung ZZ •

https://somedieyoungzz.github.io/posts/kimsuky-4/

Thumbnail for Kimsuky 4

Kimsuky targeted the Embassy of the Republic of Korea in China with a malicious Windows shortcut disguised as a familiar document. The LNK runs hidden PowerShell, locates a hardcoded shortcut size, extracts embedded bytes, launches the dropped payload, and deletes the original shortcut. The script uses Dropbox OAuth credentials to request additional staged content and includes AES decryption with the password "pa55w0rd", giving defenders concrete behaviors for shortcut, PowerShell, cloud API, and payload extraction detections.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.dropboxapi.com/oaut… 2023-12-29 2025-09-03
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
HASH fe156159a26f8b7c140db61dd8b136e… 2024-04-03 2024-04-17
URL https://api.dropboxapi.com/oaut… 2024-04-10 2024-04-10

Related Actors

Related Reports

« Back