Kimsuky A Gift That Keeps on Giving
2024-09-17 • somedieyoung ZZ •
The analysis covers a Windows LNK sample whose TTPs are assessed by the author as consistent with Kimsuky or another DPRK-based actor. The shortcut uses mshta.exe and JavaScript arguments to reach 64.49.14.181, retrieve a Base64-encoded ZIP, write it as C:\ProgramData\t.zip, extract it, and run s.vbs. The VBScript uses obfuscation and a Caesar-style decoding routine, creates a scheduled task disguised as an Edge update, and opens a decoy DOCX from ProgramData. Later stages add Run-key persistence for a VBS file and execute PowerShell against C:\ProgramData\xM578.tmp, giving defenders concrete Windows persistence and staging behaviors to hunt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 64.49.14.181 | 2024-09-17 | 2024-09-26 |
| HASH | c4aba442d881cfa112fe3a6b1d2381b… | 2024-09-17 | 2024-09-20 |
| HASH | 41cf6298a41c27357ee5f70d8cd1c0b… | 2024-09-17 | 2024-09-20 |
| HASH | b7fc11f37433b4f1d357e43b5a26802… | 2024-09-17 | 2024-09-17 |
| HASH | 2da46ae5dbabc6442cc0d2698725dae… | 2024-09-17 | 2024-09-17 |
| HASH | 40c9f86e343f5a54570162bcca2d18f… | 2024-09-17 | 2024-09-17 |