#BlueShark

Malware/Tool

2024-10-04 • 김수키(Kimsuky)그룹의 'BlueShark' 위협 전술 분석

BlueShark is a malware family linked in the source to Kimsuky activity centered on South Korea. Operators approached targets with interview, lecture, or speaking-request themes and used LNK, ISO, MSC, and HWP files. One campaign targeted North Korea specialists and selected recipients who replied for follow-on compromise. Malicious interview files were delivered through OneDrive and Proton Drive, including an HWP document and an ISO image presented as an online Zoom interview. The family name was assigned after a malicious file disguised as a lecture-request document was found on the blushaak site.

Tagged Reports

« Back