#ReconShark

Malware/Tool

2023-05-04 • Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign

ReconShark is reconnaissance malware used by the North Korean Kimsuky group against experts, organizations, and activists focused on North Korean affairs. Campaigns delivered weaponized Office documents through spear-phishing email, OneDrive links, Facebook Messenger conversations, and malicious Microsoft Management Console files disguised as private documents. ReconShark collects system information, including battery details and running processes, and communicates with command-and-control servers to transmit results, obtain decryption material, and retrieve encrypted follow-on code. Some execution paths vary according to security products detected on the infected Windows host.

Tagged Reports

« Back