#akdoor

Malware/Tool

2018-01-23 • WSF 파일 형태로 유포되는 APT 공격 주의

akdoor is a Kimsuky-linked Windows malware label covering scripted droppers and a final backdoor. Delivery methods included malicious Word documents, CHM files, and VBS or BAT scripts. Victims were induced to enable macros or open disguised files, after which scripts retrieved or created additional components. One final DLL created a process and waited for operator commands through interprocess communication. Across observed chains, individual akdoor detections represented downloader, dropper, or backdoor stages within a multi-step Kimsuky infection workflow.

Tagged Reports

« Back