Kimsuky: Infamous Threat Actor Churns Out More Advanced Malware

2023-04-19 • Zimperium •

https://www.zimperium.com/blog/kimsuky-infamous-threat-actor-churns-out-more-advanced-malware/

Thumbnail for Kimsuky: Infamous Threat Actor Churns Out More Advanced Malware

This actor, also known by Thalium and APT37, has been active since 2012 and has produced several campaigns using various techniques, from watering hole attacks to spear phishing and malware campaigns targeting different platforms, including Android and Chromium-based browsers. The latest campaign described uses different methods: - Spear Phishing Attack: The campaign uses highly targeted emails to compromise either the ultimate victim or someone in their circle and use it to perform further spear phishing attacks. These apps are distributed using a feature called “internal testing,” which allows the app developers to distribute their apps to a small group of users flagged as “trusted.” The number of trusted users is very limited, which shows that this campaign is highly targeted. This organization was detected targeting Korean and German entities, and it’s believed that the main goal is to target government employees, military, manufacturing, academic, and the think tank of global diplomacy and security.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN navernnail.com 2022-10-25 2026-01-14
DOMAIN lowerp.onlinewebshop.net 2023-04-19 2023-11-01
DOMAIN mc.pzs.kr 2022-05-18 2023-11-01
DOMAIN gonamod.com 2022-08-24 2023-05-16
IPv4 23.102.122.16 2023-04-19 2023-04-19
HASH fdd0e18e841d3ec4e501dd8bf0da682… 2022-10-25 2023-04-19
HASH 539231dea156e29bd6f7ed8430bd08a… 2022-10-25 2023-04-19
HASH 031bde16d3b75083b0adda754aa982d… 2022-10-25 2023-04-19
DOMAIN siekis.com 2022-08-24 2023-04-19

Related Actors

Related Reports

« Back