Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit

2023-05-23 • Sentinel One •

https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/

Thumbnail for Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit

SentinelLabs attributes an ongoing campaign to Kimsuky targeting North Korea-focused information services, human rights activists, and DPRK-defector support organizations. The campaign uses Korean phishing emails from Daum accounts and password-protected archives containing CHM lure files themed around difficulties faced by North Korean human rights organizations. The CHM files create and persist VBScript payloads, then contact C2 URLs such as file.com-port.space to retrieve a VBScript RandomQuery variant focused on system profiling, file enumeration, process listing, and exfiltration. RandomQuery collects hardware, operating system, Desktop, Documents, Favorites, Recent, Program Files, Downloads, and process data, Base64-encodes it, and posts it back to overlapping C2 infrastructure. The activity shows Kimsuky continuing to use CHM delivery and tailored reconnaissance tooling while registering deceptive domains under less common TLDs such as .online and .click.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bbcfcc719190f0a2c687778d5d2fd5c… 2023-05-23 2023-11-01
HASH 8c14dd8147c3c333e6f99d7f27a1620… 2023-05-23 2023-05-23
HASH ee4a54acd541dae48487514bde8730f… 2023-05-23 2023-05-23
HASH 0c723ee38c21fdfffb3fdfac20d179d… 2023-05-23 2023-05-23
HASH e60ee5a5a4cad681ece20ae31d0b060… 2023-05-23 2023-05-23
HASH 8f2e6719ce0f29c2c6dbabe5a7bda59… 2023-05-23 2023-05-23

Related Actors

Related Reports

« Back