#KimsuKEE
Incident/Operation
2019-05-10 • Operation KimsuKEE(Kimsuky Eternal Evolution)
KimsuKEE, short for Kimsuky Eternal Evolution, designates a Kimsuky malware sample tracked as KIMSUKY-04 rather than a distinct threat actor. The sample used a malicious HWP document whose embedded PostScript exploited the document processor and loaded shellcode into memory. Its follow-on behavior reflected established Kimsuky installation patterns: dropping additional malware from a PE resource section or downloading it from external infrastructure, then collecting system information and other data through command-and-control. The designation highlights an evolving implementation within Kimsuky's long-running South Korea-focused intrusion activity.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days