Kimsuky group appears to be exploiting OneNote like the cybercrime group
2023-03-17 • S2W •
S2W reported that Kimsuky was distributing malware with a malicious Microsoft OneNote file, a delivery technique more commonly seen in cybercrime campaigns. The lure impersonated Korea University’s Institute for Peace and Democracy and asked survey participants to open what appeared to be a privacy-agreement HWP file for recompense, but clicking the embedded object executed hidden VBS. The script attempted to download a decoy HWP and additional code from delps.scienceontheweb.net, using a list.php?query=1 URL pattern and hosting infrastructure previously associated with Kimsuky Babyshark activity. The final payload was not recovered, but the recompense theme, URL format, and 185.176.43[.]98 infrastructure supported the report’s Kimsuky attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 185.176.43.98 | 2023-03-17 | 2026-09-22 |
| DOMAIN | delps.scienceontheweb.net | 2023-03-17 | 2024-12-16 |
| HASH | 1334ef6ae02e3d0581f3ac177aec766… | 2023-03-17 | 2023-05-24 |
| HASH | 29e17b37a49218c644b8c7dcd981716… | 2023-03-17 | 2023-05-24 |
| URL | http://delps.scienceontheweb.ne… | 2023-03-17 | 2023-03-20 |
| URL | http://delps.scienceontheweb.ne… | 2023-03-17 | 2023-03-20 |