Kimsuky Targets South Korean Research Institutes with Fake Import Declaration

2023-11-30 • Ahnlab •

https://asec.ahnlab.com/en/59387/

Thumbnail for Kimsuky Targets South Korean Research Institutes with Fake Import Declaration

ASEC reports that Kimsuky distributed a malicious JSE file disguised as an import declaration to South Korean research institutes. The dropper contains obfuscated PowerShell, a Base64-encoded Nikidoor backdoor, and a decoy PDF that displays victim-specific content while the malware runs in the background. The backdoor is written into ProgramData, executed through rundll32.exe, copied as IconCache.db for persistence, and registered as a scheduled task named iconcache. It collects anti-malware, network, host, user, and OS information with commands such as wmic and ipconfig, encodes command output, and communicates with rscnode.dothome.co.kr endpoints for upload and command execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 97df5304f53fec6a5d2d2bd75b9310a… 2023-11-21 2024-03-05
HASH b1361b67025b44a86af61c1863c98fb… 2023-11-21 2023-11-30
URL http://rscnode.dothome.co.kr/in… 2023-11-21 2023-11-30
URL http://rscnode.dothome.co.kr/up… 2023-11-21 2023-11-30
DOMAIN rscnode.dothome.co.kr 2023-11-21 2023-11-30

Related Actors

Related Reports

« Back