Kimsuky group appears to be exploiting OneNote like the cybercrime group

2023-03-17 • S2W •

https://medium.com/s2wblog/kimsuky-group-appears-to-be-exploiting-onenote-like-the-cybercrime-group-3c96b0b85b9f

Thumbnail for Kimsuky group appears to be exploiting OneNote like the cybercrime group

S2W reported that Kimsuky was distributing malware with a malicious Microsoft OneNote file, a delivery technique more commonly seen in cybercrime campaigns. The lure impersonated Korea University’s Institute for Peace and Democracy and asked survey participants to open what appeared to be a privacy-agreement HWP file for recompense, but clicking the embedded object executed hidden VBS. The script attempted to download a decoy HWP and additional code from delps.scienceontheweb.net, using a list.php?query=1 URL pattern and hosting infrastructure previously associated with Kimsuky Babyshark activity. The final payload was not recovered, but the recompense theme, URL format, and 185.176.43[.]98 infrastructure supported the report’s Kimsuky attribution.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 185.176.43.98 2023-03-17 2026-09-22
DOMAIN delps.scienceontheweb.net 2023-03-17 2024-12-16
HASH 1334ef6ae02e3d0581f3ac177aec766… 2023-03-17 2023-05-24
HASH 29e17b37a49218c644b8c7dcd981716… 2023-03-17 2023-05-24
URL http://delps.scienceontheweb.ne… 2023-03-17 2023-03-20
URL http://delps.scienceontheweb.ne… 2023-03-17 2023-03-20

Related Actors

Related Reports

« Back